In-Sight Explorer and Camera Firmware Security Flaw from Cognex
CVE-2025-54818

8.6HIGH

Key Information:

Vendor

Cognex

Vendor
CVE Published:
18 September 2025

What is CVE-2025-54818?

Cognex's In-Sight Explorer and In-Sight Camera Firmware present a security concern due to the exposure of a proprietary protocol over TCP port 1069. This vulnerability allows unauthorized management operations, including alterations to system properties. Additionally, the user management features transmit sensitive information such as usernames and passwords through an unencrypted channel, making it possible for adjacent attackers to intercept valid credentials and potentially gain unauthorized access to the devices.

Affected Version(s)

In-Sight 2000 series 5.x <= 6.5.1

In-Sight 7000 series 5.x <= 6.5.1

In-Sight 8000 series 5.x <= 6.5.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.
.
CVE-2025-54818 : In-Sight Explorer and Camera Firmware Security Flaw from Cognex