CVE-2025-54818

8.0

Cognex · In-Sight Explorer and In-Sight Camera Firmware

Cognex In-Sight devices expose a proprietary protocol on TCP port 1069 that transmits sensitive user credentials over an unencrypted channel, allowing adjacent attackers to intercept valid logins.

Executive summary

Cognex In-Sight Explorer and camera firmware are vulnerable to credential interception due to unencrypted communication, posing a significant risk of unauthorized administrative access.

Vulnerability

The device exposes a proprietary management protocol on TCP port 1069 that transmits usernames and passwords in cleartext. This allows an unauthenticated, adjacent attacker to perform credential harvesting via traffic interception.

Business impact

Successful exploitation allows an attacker to obtain valid administrative credentials for industrial control systems. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to unauthorized system modification, operational disruption, or total loss of control over the affected Cognex hardware.

Remediation

Immediate Action: Review the official CISA advisory (ICSA-25-261-06) and apply the latest firmware or software updates provided by Cognex as soon as they become available.

Proactive Monitoring: Monitor network traffic directed to TCP port 1069 for anomalous connection patterns or unauthorized access attempts from unexpected segments.

Compensating Controls: Implement network segmentation to isolate Cognex devices from untrusted network segments, restricting access to port 1069 to authorized management workstations only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Cognex In-Sight systems must treat this vulnerability with high priority. Because the flaw allows for the direct interception of administrative credentials, immediate network segmentation is required to mitigate the risk until official patches can be validated and deployed to all affected production hardware.

More Cognex CVEs

Sources

Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.