CVE-2025-53969

8.8

Cognex · In-Sight Explorer and In-Sight Camera Firmware

Cognex In-Sight Explorer and firmware expose a proprietary protocol on TCP port 1069, allowing authenticated users to perform unauthorized management operations, including network and access changes.

Executive summary

A high-severity vulnerability in Cognex In-Sight products allows authenticated attackers to perform unauthorized device management operations, potentially leading to a complete loss of device control.

Vulnerability

This vulnerability involves improper enforcement of client-side restrictions (CWE-602) within a proprietary protocol on TCP port 1069, where an authenticated user with low privileges can perform administrative management operations.

Business impact

The ability for an attacker to modify network settings or user access controls directly impacts the integrity and availability of industrial vision systems. With a CVSS score of 8.8, this flaw presents a significant risk to operational technology environments, as unauthorized configuration changes could result in system downtime or the compromise of restricted security zones.

Remediation

Immediate Action: Review the official CISA advisory (ICSA-25-261-06) for specific firmware update availability and apply all recommended patches to affected devices immediately.

Proactive Monitoring: Monitor network traffic for unauthorized communication directed at TCP port 1069 and review device logs for unexpected configuration changes or user modifications.

Compensating Controls: Restrict network access to the affected devices by implementing firewall rules that limit communication on TCP port 1069 to authorized management workstations only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the potential for total impact on device management, organizations should prioritize the identification of all vulnerable Cognex hardware within their network. Administrators must restrict access to the vulnerable port immediately and apply vendor-supplied firmware updates as soon as they become available to eliminate the risk of unauthorized administrative manipulation.

More Cognex CVEs

Sources

Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.