PT-2025-38489 · Cognex · Cognex In-Sight Explorer+1

Diego Giubertoni

·

Published

2025-09-18

·

Updated

2025-09-19

·

CVE-2025-54497

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cognex In-Sight Explorer and In-Sight Camera Firmware (affected versions not specified)
Description The software exposes a telnet-based service on port 23, intended for management operations like firmware upgrades and device reboots that require authentication. A user with protected privileges can utilize the SetSerialPort functionality to modify device properties, including serial interface settings, which contradicts the documented security model.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-54497

Affected Products

Cognex In-Sight Camera Firmware
Cognex In-Sight Explorer