PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34022 Wertheim GmbH CVE debrief

The Wertheim SafeController Family 65000, specifically Controller 65000 with AssemblyVersion 6.11.8130.22319, employs weak custom cryptographic algorithms with hard-coded cryptographic keys to secure communication. This vulnerability enables an adversary-in-the-middle to decrypt data traffic. Furthermore, during reassessment, it was found possible to break the encryption/decryption routine and decrypt messages without needing the encryption key. Additionally, intercepting a sufficient number of messages could reveal the encryption key.

Vendor
Wertheim GmbH
Product
Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of the Wertheim SafeController Family 65000, specifically those with Controller 65000 running AssemblyVersion 6.11.8130.22319, should be aware of this vulnerability as it could allow attackers to intercept and decrypt their communication.

Technical summary

The vulnerability involves the use of weak custom cryptographic algorithms with hard-coded keys in the Wertheim SafeController Family 65000. This allows for the decryption of data traffic by an attacker in an adversary-in-the-middle position. The encryption can be broken, and messages can be decrypted without the encryption key. The encryption key can also be determined by intercepting enough messages.

Defensive priority

High

Recommended defensive actions

  • Update to a version of Controller 65000 that uses secure cryptographic algorithms and practices.
  • Implement secure key management practices to prevent the use of hard-coded keys.
  • Use secure communication protocols that are resistant to interception and decryption by unauthorized parties.
  • Monitor communication for signs of tampering or interception.

Evidence notes

Evidence suggests that the vendor, referred to as 'Unknown Vendor' with low confidence, has a product affected by this vulnerability. The canonical source for this information is noted as 'reference_domain_weak' with evidence from 'Sec Consult'.

Official resources

CVE-2026-34022 was published and modified on 2026-06-15T12:16:24.410Z.