CVE-2025-54818 describes a critical vulnerability in Cognex In-Sight Explorer and Camera Firmware, where a proprietary management protocol on TCP port 1069 transmits sensitive user credentials, including usernames and passwords, over an unencrypted channel. This allows an adjacent attacker to intercept valid credentials, leading to unauthorized access and potential compromise of the device. With a CVSS score of 8.0 (HIGH), the vulnerability has a low attack complexity and requires no user interaction, enabling a high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cognex | In-Sight 2000 Series | >= 5.x, <= 6.5.1CNA affecteddefault unaffected | |
| Cognex | In-Sight 7000 Series | >= 5.x, <= 6.5.1CNA affecteddefault unaffected | |
| Cognex | In-Sight 8000 Series | >= 5.x, <= 6.5.1CNA affecteddefault unaffected | |
| Cognex | In-Sight 9000 Series | >= 5.x, <= 6.5.1CNA affecteddefault unaffected | |
| Cognex | In-Sight Explorer | >= 5.x, <= 6.5.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.