CVE-2025-54754
8.0Cognex · In-Sight Series and In-Sight Explorer
A hard-coded password vulnerability in Cognex In-Sight devices allows unauthenticated, adjacent attackers to retrieve credentials and decrypt sensitive network traffic.
Executive summary
Cognex In-Sight devices are vulnerable to a hard-coded credential flaw that permits unauthenticated attackers with adjacent network access to decrypt sensitive traffic.
Vulnerability
This vulnerability involves the use of hard-coded credentials (CWE-259) embedded within the software. An unauthenticated attacker located on the adjacent network can extract these credentials to intercept and decrypt sensitive network communications.
Business impact
The ability for an unauthorized party to decrypt sensitive network traffic poses a severe risk to operational security and data confidentiality. Given the CVSS score of 8.0 (High), this vulnerability could facilitate unauthorized access to industrial control systems or sensitive configuration data, potentially leading to operational disruption or further exploitation of the internal network.
Remediation
Immediate Action: Review the official CISA ICS advisory (ICSA-25-261-06) and apply the latest vendor-supplied firmware or software updates as soon as they are made available by Cognex.
Proactive Monitoring: Monitor network traffic for unusual patterns or attempts to access administrative interfaces on In-Sight devices from unauthorized segments.
Compensating Controls: Restrict network access to Cognex devices by placing them on isolated VLANs and using firewalls to limit connectivity to authorized personnel only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The reliance on hard-coded passwords creates a critical security gap in affected Cognex environments. Administrators should prioritize identifying all vulnerable hardware and software instances and prepare to implement vendor-provided patches immediately upon release. Until patches are applied, strict network segmentation is required to mitigate the risk of adjacent access by malicious actors.
More Cognex CVEs
Sources
Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.