logo

Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform

ID: 8f550e1f-3e13-5582-80fd-3817e0dcb772

STIX ID: report--8f550e1f-3e13-5582-80fd-3817e0dcb772

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-06-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

CISA and security researchers disclosed two critical, unpatched vulnerabilities in Consilium CS5000 fire panels (CVE-2025-41438 and CVE-2025-46352) that allow remote takeover via a default account and a hardcoded VNC password; Consilium recommends replacing affected units rather than patching, and CISA advises compensating controls to mitigate significant physical-safety risks across an estimated 85,000 installed devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.