Telnet-Based Service Vulnerability in Cognex In-Sight Explorer and Camera Firmware
CVE-2025-52873
7.2HIGH
What is CVE-2025-52873?
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based management service on port 23. This service allows for management operations, such as firmware upgrades and device reboots, which are intended to be accessed only with authentication. However, a user with secured privileges can exploit this service to access the SetSystemConfig functionality, enabling them to modify crucial device properties, including network settings. This undermines the security model outlined in the user manual, posing a risk to device integrity.
Affected Version(s)
In-Sight 2000 series 5.x <= 6.5.1
In-Sight 7000 series 5.x <= 6.5.1
In-Sight 8000 series 5.x <= 6.5.1
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.