CVE-2025-54860

7.7

Cognex · In-Sight Explorer and In-Sight Camera Firmware

Cognex In-Sight Explorer and firmware versions 5.x through 6.5.1 are vulnerable to a denial of service condition in the telnet management service due to improper handling of login failures.

Executive summary

A vulnerability in the Cognex In-Sight telnet service allows an authenticated attacker to trigger a denial of service condition, potentially rendering management functions unreachable.

Vulnerability

This vulnerability, classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts), affects the telnet-based management service on port 23. An attacker with local access and valid credentials can trigger a denial of service by intentionally failing login attempts, causing the service to become unresponsive.

Business impact

The exploitation of this vulnerability results in a denial of service, which prevents authorized personnel from performing critical management tasks such as firmware upgrades or device reboots. Given the CVSS score of 7.7, this represents a high-severity risk to operational continuity, especially in industrial environments where remote management of camera systems is essential for production monitoring.

Remediation

Immediate Action: Review the official CISA advisory (ICSA-25-261-06) for vendor-specific patch availability and apply firmware updates to all affected Cognex In-Sight devices as soon as they are released.

Proactive Monitoring: Monitor network traffic to port 23 for unusual spikes in authentication failures or sudden service outages associated with In-Sight device management.

Compensating Controls: Restrict access to the telnet service (port 23) using network segmentation or firewall rules to ensure only authorized management workstations can communicate with the devices.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Cognex In-Sight systems should prioritize the identification of all affected hardware versions within their network infrastructure. While no patch is currently identified, administrators must restrict access to the management interface immediately and prepare for deployment of vendor updates to mitigate the risk of service disruption.

More Cognex CVEs

Sources

Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.