CVE-2025-53969 Details
Description
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device.
A vulnerability exists in Cognex In-Sight Explorer and In-Sight Camera Firmware, all versions through 6.5.1, allowing client-side software to perform unauthorized management operations via a proprietary protocol on TCP port 1069. This could include changing network settings or modifying user access. The issue arises from improper enforcement of security protocols, enabling potential exploitation by intercepting and replaying authentication credentials.
Cognex advises users to transition to next-generation In-Sight Vision Suite-based systems, such as the In-Sight 2800, In-Sight 3800, or In-Sight 8900 series embedded cameras. For additional guidance, refer to the CISA ICS webpage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2025CISA-ADP
Assessed Sep 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-261-06 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cognex In-Sight Explorer | All versions |
CPE
Remediation
| |
| Cognex In-Sight 2000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 7000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 8000 | All versions |
CPE
Remediation
| |
| Cognex In-Sight 9000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | New CVE Received | [email protected] |
Volerion