CVE Explorer
CVE-2026-34022
The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to break the encryption/decryption routine and decrypt messages without knowledge of the encryption key. It was also possible to gain knowledge about the encryption key by intercepting
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)","vendor":"Wertheim GmbH","versions":[{"status":"affected","version":"Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.1,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-321","description":"CWE-321 Use of hard-coded cryptographic key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["third-party-advisory"],"url":"https://r.sec-consult.com/wertdev"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-wertheim-safecontroller-hardware-for-vault-rooms-safe-deposit-locker-system-microcontroller/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/adp/0/references/0
{"tags":["product"],"url":"https://wertheim-safes.com/safe-deposit-boxes/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ed9743adbe29c4fd1675f62e6209eb92f1192bb0f71b9c1d3fe42e7b07ee0569 · sha256:18f212b1d357d5ac… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.