Watchfire Controller Software

MonitorCVSS 5.7ICS-CERT ICSA-26-211-09Jul 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionRequired
Summary

Watchfire controller software contains a vulnerability in certificate handling that could allow a malicious user with administrative credentials and user interaction capability to deliver malicious firmware and gain full control of the affected controller. The vulnerability stems from improper validation of firmware signatures, permitting an attacker to bypass security checks during firmware updates. Affected models include BC550, BC750, BC760, and BC760DC controllers across multiple firmware versions. Watchfire has released security patches that disable the use of the existing certificate and require stricter validation for all future updates.

What this means
What could happen
An attacker with high-level access and ability to interact with the controller could deliver malicious firmware to gain full control of the Watchfire controller, potentially altering display content, timing, or operations that depend on the billboard system.
Who's at risk
This vulnerability affects Watchfire billboard and message display controllers (BC550, BC750, BC760, and BC760DC models) used in transportation, municipal, and commercial signage operations. Organizations managing these display systems should prioritize patching to prevent unauthorized firmware injection.
How it could be exploited
An attacker with administrative-level credentials and user interaction (such as the ability to prompt a user to approve an update) could exploit insecure certificate handling to deliver unsigned or maliciously signed firmware. The attacker would need network access to the controller and must have high-level privileges combined with social engineering or physical access to trigger the update process.
Prerequisites
  • Administrator or high-privilege credentials for the Watchfire controller
  • Network access to the controller management interface
  • User interaction required (administrator must approve or initiate a firmware update)
  • Knowledge of or ability to bypass certificate validation mechanisms
remotely exploitablehigh privilege required for exploitationuser interaction requiredaffects control system firmware integrityinsecure certificate handling
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (4)
1 with fix3 pending
ProductAffected VersionsFix Status
BC550: 12.3012.30Fix available
BC750: 11.33|12.3511.33|12.35No fix yet
BC760: 12.38|13.0012.38|13.00No fix yet
BC760DC: 12.3912.39No fix yet
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict network access to controller management interfaces to authorized administrative networks or VPNs
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

HOTFIXUpdate BC550 controllers to firmware version 12.31 SP1 or later
HOTFIXUpdate BC750 controllers running version 11.33 to firmware version 11.34 or later
HOTFIXUpdate BC750 controllers running version 12.35 to firmware version 12.36 SP1 or later
HOTFIXUpdate BC760 controllers running version 12.38 to firmware version 12.41 SP1 or later
HOTFIXUpdate BC760 controllers running version 13.00 to firmware version 14.00 SP1 or later
HOTFIXUpdate BC760DC controllers to firmware version 12.41 SP1 or later
API: /api/v1/advisories/4805037e-e6dc-4aea-8f01-ab6567810110

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.