CVE-2025-54497
8.1Cognex · In-Sight Explorer and In-Sight Camera Firmware
Cognex In-Sight products expose a Telnet service on port 23 that allows authenticated users with protected privileges to improperly modify device properties via the SetSerialPort functionality.
Executive summary
A vulnerability in Cognex In-Sight Explorer and Camera Firmware allows authenticated users to bypass intended security controls and modify device properties via a Telnet interface.
Vulnerability
The device exposes a Telnet service on port 23 that permits authenticated users to invoke the SetSerialPort functionality to alter device properties, which violates the established security model.
Business impact
The ability for a low-privileged or authenticated user to modify critical device properties poses a significant risk to operational integrity. Unauthorized changes to serial interface settings could lead to the loss of device control, operational disruption, or potential safety hazards in industrial environments. With a CVSS score of 8.1, this vulnerability is classified as High severity due to the potential for significant integrity and availability impact on industrial control systems.
Remediation
Immediate Action: Consult the official CISA ICS advisory ICSA-25-261-06 for the latest firmware guidance and disable the Telnet service on affected devices if it is not required for operations.
Proactive Monitoring: Monitor network traffic for unauthorized connections to TCP port 23 and audit authentication logs for unusual activity involving administrative or protected service accounts.
Compensating Controls: Implement network segmentation to restrict access to the Telnet service to only trusted management workstations and utilize firewalls to block external access to port 23.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the industrial nature of the affected hardware, organizations should prioritize restricting network access to these devices immediately. Administrators must review the vendor documentation linked in the CISA advisory to determine if a firmware update is available for their specific model and apply it as soon as it is released to restore the integrity of the device security model.
More Cognex CVEs
Sources
Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.