Management Protocol Vulnerability in Cognex In-Sight Explorer and Camera Firmware
CVE-2025-54810

8.6HIGH

Key Information:

Vendor

Cognex

Vendor
CVE Published:
18 September 2025

What is CVE-2025-54810?

Cognex In-Sight Explorer and In-Sight Camera Firmware utilize a proprietary management protocol exposed on TCP port 1069. This protocol facilitates administrative actions such as altering system settings. However, it transmits sensitive information, including registered usernames and passwords, over an unencrypted channel. This poses a risk, as adjacent attackers could potentially intercept valid credentials, compromising the security of the device and unauthorized access.

Affected Version(s)

In-Sight 2000 series 5.x <= 6.5.1

In-Sight 7000 series 5.x <= 6.5.1

In-Sight 8000 series 5.x <= 6.5.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.
.
CVE-2025-54810 : Management Protocol Vulnerability in Cognex In-Sight Explorer and Camera Firmware