CVE-2025-54754 Details
Description
An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device.
A vulnerability exists in Cognex In-Sight 2000, 7000, 8000, and 9000 series products, as well as In-Sight Explorer, all running versions 5.x up to and including 6.5.1. This vulnerability allows an adjacent attacker, without authentication, to extract a hard-coded password from publicly available software. This password can be used to decrypt sensitive network traffic, impacting the affected Cognex device.
Cognex advises users to transition to next-generation In-Sight Vision Suite-based systems, such as the In-Sight 2800, 3800, or 8900 series embedded cameras. For additional guidance, refer to the CISA ICS webpage and the technical information paper ICS-TIP-12-146-01B.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2025CISA-ADP
Assessed Sep 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-261-06 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cognex In-Sight Explorer | All versions |
CPE
Remediation
| |
| Cognex In-Sight 2000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 7000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 8000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 9000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | New CVE Received | [email protected] |
Volerion