CVE-2025-52873
8.1Cognex · In-Sight Explorer and In-Sight Camera Firmware
Cognex In-Sight devices expose a telnet service on port 23 that fails to enforce security model restrictions, allowing authenticated users to modify device properties via the SetSystemConfig function.
Executive summary
A vulnerability in Cognex In-Sight firmware and Explorer software allows authenticated users to perform unauthorized configuration changes, posing a significant risk to industrial device integrity.
Vulnerability
This is a privilege management issue (CWE-732) where the SetSystemConfig functionality incorrectly permits low-privileged authenticated users to alter sensitive device properties, such as network configurations. The vulnerability contradicts the intended security model and allows unauthorized administrative actions over a telnet connection.
Business impact
Successful exploitation of this flaw could allow an authenticated attacker to alter network settings or disrupt operations, leading to unauthorized control of industrial vision systems. With a CVSS score of 8.1, this vulnerability represents a high risk to operational continuity and system integrity, as it facilitates the modification of critical device parameters that should remain restricted.
Remediation
Immediate Action: Restrict network access to port 23 to only authorized administrative workstations until a vendor-supplied firmware update is available.
Proactive Monitoring: Review system access logs for any unauthorized use of the telnet service or unexpected calls to the SetSystemConfig function.
Compensating Controls: Implement strict network segmentation or use a firewall to isolate the telnet service from untrusted network segments.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in our data.
Analyst recommendation
Given the high severity of this vulnerability, administrators should prioritize the isolation of affected Cognex devices from broader network access. While waiting for official patches from Cognex, limiting access to the telnet interface is the most effective method to mitigate the risk of unauthorized configuration changes.
More Cognex CVEs
Sources
Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.