this vulnerability to retrieve a hard-coded password embedded in
publicly available software. This password can then be used to decrypt
sensitive network traffic, affecting the Cognex device.
Subscriptions
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30191 | An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device. |
Solution
No solution given by the vendor.
Workaround
Cognex reports that In-Sight Explorer based vision systems are legacy products not intended for new applications. To reduce risk, asset owners are advised to switch to next generation In-Sight Vision Suite based vision systems, such as the In-Sight 2800, In-Sight 3800, In-Sight 8900 series embedded cameras.
Fri, 19 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cognex
Cognex in-sight Camera Firmware Cognex in-sight Explorer |
|
| Vendors & Products |
Cognex
Cognex in-sight Camera Firmware Cognex in-sight Explorer |
Thu, 18 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device. | |
| Title | Cognex In-Sight Explorer and In-Sight Camera Firmware Use of Hard-coded Password | |
| Weaknesses | CWE-259 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-19T13:04:14.180Z
Reserved: 2025-08-06T16:32:41.245Z
Link: CVE-2025-54754
Updated: 2025-09-19T13:04:02.440Z
Status : Awaiting Analysis
Published: 2025-09-18T21:15:48.317
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-54754
No data.
OpenCVE Enrichment
Updated: 2025-09-19T09:35:23Z
EUVD