PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34022 Wertheim GmbH CVE debrief

The Wertheim SafeController Family 65000, specifically Controller 65000 with AssemblyVersion 6.11.8130.22319, employs weak custom cryptographic algorithms with hard-coded cryptographic keys to secure communication. This vulnerability enables an adversary-in-the-middle to decrypt data traffic. Furthermore, during reassessment, it was found possible to break the encryption/decryption routine and decrypt messages without needing the encryption key. Additionally, intercepting a sufficient number of messages could reveal the encryption key.

Vendor
Wertheim GmbH
Product
Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of the Wertheim SafeController Family 65000, specifically those with Controller 65000 running AssemblyVersion 6.11.8130.22319, should be aware of this vulnerability as it could allow attackers to intercept and decrypt their communication.

Technical summary

The vulnerability involves the use of weak custom cryptographic algorithms with hard-coded keys in the Wertheim SafeController Family 65000. This allows for the decryption of data traffic by an attacker in an adversary-in-the-middle position. The encryption can be broken, and messages can be decrypted without the encryption key. The encryption key can also be determined by intercepting enough messages.

Defensive priority

High

Recommended defensive actions

  • Update to a version of Controller 65000 that uses secure cryptographic algorithms and practices.
  • Implement secure key management practices to prevent the use of hard-coded keys.
  • Use secure communication protocols that are resistant to interception and decryption by unauthorized parties.
  • Monitor communication for signs of tampering or interception.

Evidence notes

Evidence suggests that the vendor, referred to as 'Unknown Vendor' with low confidence, has a product affected by this vulnerability. The canonical source for this information is noted as 'reference_domain_weak' with evidence from 'Sec Consult'.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-34022 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-34022

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-34022 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34022

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://r.sec-consult.com/wertdev

    551230f0-3615-47bd-b7cc-93e92e730bbf

  • Source reference

    Unverified legacy reference

    URL: https://wertheim-safes.com/safe-deposit-boxes/

    551230f0-3615-47bd-b7cc-93e92e730bbf

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.