Skip to content
June 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CISA Alert: Critical Flaws in Consilium Safety CS5000 Fire Panel Could Enable Remote Takeover, No Patch
  • Vulnerability Report

CISA Alert: Critical Flaws in Consilium Safety CS5000 Fire Panel Could Enable Remote Takeover, No Patch

Do Son June 2, 2025 3 minutes read
0
Consilium Safety, Fire Panel Vulnerabilities
Add as a preferred
source on Google

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning of two critical security vulnerabilities affecting all versions of the Consilium Safety CS5000 Fire Panel—a widely deployed industrial control system used in fire safety environments. If exploited, these flaws could allow remote attackers to gain high-level access and potentially render fire panels non-functional, posing significant risks to safety-critical infrastructure.

“Successful exploitation of these vulnerabilities could allow an attacker to gain high-level access to and remotely operate the device, potentially putting it into a non-functional state,” the advisory warns.

The first vulnerability, identified as CVE-2025-41438, involves the initialization of a system resource with an insecure default configuration. A default high-privileged account exists on all CS5000 units and is observed to remain unchanged in production environments.

“Even though it is possible to change this by SSHing into the device, it has remained unchanged on every installed system observed,” the report states.

While the account is not root-level, it still possesses sufficient privileges to critically disrupt operations. The flaw has received a CVSS v3.1 base score of 9.8, reflecting its critical severity.

The second vulnerability, CVE-2025-46352, stems from the presence of hard-coded credentials in a VNC server component used by the fire panel. The password is embedded within the binary and cannot be changed, granting anyone with knowledge of it full remote access to the system.

“This password cannot be altered, allowing anyone with knowledge of it to gain remote access… potentially putting the fire panel into a non-functional state and causing serious safety issues,” according to CISA’s technical bulletin.

This vulnerability has also received a CVSS score of 9.8, underscoring the severe impact and ease of exploitation.

Both vulnerabilities were responsibly disclosed by Andrew Tierney of Pen Test Partners, who reported the issues to CISA. As of now, no public exploitation of these flaws has been reported.

Alarmingly, Consilium Safety has no plans to patch the CS5000 Fire Panel. Instead, the vendor recommends migrating to newer hardware models.

“Users wanting enhanced security features are advised to upgrade to Consilium Safety’s newer line of fire panels… manufactured after July 1, 2024,” the advisory states.

Until then, customers are encouraged to apply compensating controls, including physical security measures and restricted administrative access to CS5000 devices.

CISA urges affected organizations to minimize risk by adopting the following best practices:

  • Isolate fire panels from internet exposure and place them behind firewalls.
  • Segment control system networks from business environments.
  • Use updated VPNs for remote access and secure all connected endpoints.

More details are available through the official Consilium Safety support site and CISA ICS Alert.

Related Posts:

  • Urgent Security Alert for Siemens Fire Protection Systems: Critical Vulnerabilities Discovered
  • CVE-2024-22039 (CVSS 10): Siemens Fire Protection Systems Vulnerable to Remote Attacks
  • Microsoft Signals End of an Era: Control Panel to be Phased Out
  • WikiLeaks Share Trump book Fire and Fury, but Google Drive removed it
  • CEO Google Sundar Pichai: the importance of AI can be comparable to electricity and fire

Related coverage

  • Critical XCharge C6 Vulnerabilities Expose Electric Vehicle Chargers
  • CVE-2024-36401 Exploited in Stealthy Bandwidth-Monetization Campaign
  • BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender
  • CUPS Flaws Allow Linux Remote DoS (CVE-2025-58364) and Authentication Bypass (CVE-2025-58060)
  • Fragnesia Universal Linux Root LPE Details and One-Line PoC Disclosed

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: CISA Consilium Safety Critical Infrastructure CS5000 cybersecurity default account fire panel hardcoded credentials ICS industrial control systems Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
  • CVE-2024-23692CVSS 9.8
    Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-48907
    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated...
  • CVE-2026-20253CVSS 9.8
    In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-20182CVSS 10.0
    May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-39955CVSS 9.8
    Cacti is an open source performance and fault management framework. Versions 1.2.30...
  • CVE-2026-39938CVSS 9.8
    Cacti is an open source performance and fault management framework. Versions 1.2.30...
  • CVE-2026-55570CVSS 9.0
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it...
  • CVE-2026-55454CVSS 9.9
    Appsmith is a platform to build admin panels, internal tools, and dashboards....
  • CVE-2026-54158CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the...
  • CVE-2026-54067CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS...
  • CVE-2026-50551CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan...
  • CVE-2026-39893CVSS 9.8
    Cacti is an open source performance and fault management framework. In versions...
  • CVE-2026-52813CVSS 10.0
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization...
  • CVE-2026-52806CVSS 9.9
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.