CVE 8.1 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical Resource_CVE-2025-54497

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Description

Cognex In-Sight Explorer and In-Sight Camera Firmware expose
a telnet-based service
on port 23 to allow management operations such as firmware upgrades and
device reboots, which require authentication. A user with protected
privileges can successfully invoke the SetSerialPort functionality to
modify relevant device properties (such as serial interface settings),
contradicting the security model proposed in the user manual.

Basic Information

ID CVE-2025-54497
Source icscert
Published Sep 18, 2025 at 21:24

Affected Product

Vendor Cognex
Product In-Sight 2000 series
Version 5.x
Affected Versions Cognex In-Sight 2000 series 5.x
Cognex In-Sight 7000 series 5.x
Cognex In-Sight 8000 series 5.x
Cognex In-Sight 9000 series 5.x
Cognex In-Sight Explorer 5.x

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.