Home

Description

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device properties (such as network settings), contradicting the security model proposed in the user manual.

PUBLISHED Reserved 2025-08-06 | Published 2025-09-18 | Updated 2025-09-19 | Assigner icscert




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

HIGH: 7.2CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-732

Product status

Default status
unaffected

5.x (custom)
affected

Default status
unaffected

5.x (custom)
affected

Default status
unaffected

5.x (custom)
affected

Default status
unaffected

5.x (custom)
affected

Default status
unaffected

5.x (custom)
affected

Credits

Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-261-06

cve.org (CVE-2025-52873)

nvd.nist.gov (CVE-2025-52873)

Download JSON