CVE-2025-54497

HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware - Privilege E...

Title source: llm
STIX 2.1

Description

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

Scores

CVSS v3 8.1
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (5)
Cognex/In-Sight 2000 series 5.x - 6.5.1
Cognex/In-Sight 7000 series 5.x - 6.5.1
Cognex/In-Sight 8000 series 5.x - 6.5.1
Cognex/In-Sight 9000 series 5.x - 6.5.1
Cognex/In-Sight Explorer 5.x - 6.5.1
Published Sep 18, 2025
Tracked Since Feb 18, 2026