CVE-2025-52873
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/09/2025
Last modified:
19/09/2025
Description
Cognex In-Sight Explorer and In-Sight Camera Firmware expose <br />
a telnet-based service on port 23 to allow management operations such as<br />
firmware upgrades and device reboots, which require authentication. A <br />
user with protected privileges can successfully invoke the <br />
SetSystemConfig functionality to modify relevant device properties (such<br />
as network settings), contradicting the security model proposed in the <br />
user manual.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH