CVE-2025-7741 identifies a hardcoded password vulnerability (CWE-259) in CENTUM VP versions R5.01.00 through R5.04.20, R6.01.00 through R6.12.00, and R7.01.00, involving a fixed password for the 'PROG' user account. Exploitation is highly complex, requiring an attacker to obtain the password and already have direct or remote access to the HIS screen controls configured in CTM authentication mode. The severity is rated low (CVSS 2.1) because the default PROG user permissions are limited, and an attacker would already possess operational access to the system before leveraging this vulnerability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Yokogawa Electric Corporation | CENTUM VP | >= R5.01.00, <= R5.04.20, >= R6.01.00, <= R6.12.00, R7.01.00CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.