CVE-2025-54497: Cognex In-Sight 2000 Series

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

Affected products

  • Cognex In-Sight 2000 Series: from 5, up to and including 6.5.1
  • Cognex In-Sight 7000 Series: from 5, up to and including 6.5.1
  • Cognex In-Sight 8000 Series: from 5, up to and including 6.5.1
  • Cognex In-Sight 9000 Series: from 5, up to and including 6.5.1
  • Cognex In-Sight Explorer: from 5, up to and including 6.5.1

Published 2025-09-18. Last modified 2026-06-17.