Telnet Service Vulnerability in Cognex In-Sight Explorer and Camera Firmware
CVE-2025-54497

7.2HIGH

Key Information:

Vendor

Cognex

Vendor
CVE Published:
18 September 2025

What is CVE-2025-54497?

The Cognex In-Sight Explorer and In-Sight Camera Firmware are affected by a vulnerability that exposes a telnet-based service on port 23. This service, which is intended for legitimate management operations such as firmware upgrades and device reboots, requires user authentication. However, a user with protected privileges can exploit the SetSerialPort functionality to make unauthorized changes to critical device properties, including serial interface settings. This situation contradicts the security protocols outlined in the user manual, potentially leading to unauthorized access and manipulation of device operations.

Affected Version(s)

In-Sight 2000 series 5.x <= 6.5.1

In-Sight 7000 series 5.x <= 6.5.1

In-Sight 8000 series 5.x <= 6.5.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.
.
CVE-2025-54497 : Telnet Service Vulnerability in Cognex In-Sight Explorer and Camera Firmware