CVE-2025-53969
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-602
- Published
- 2025-09-18
- Last modified
- 2026-03-13
Affected products
- Cognex In-Sight 2000 series
- Cognex In-Sight 7000 series
- Cognex In-Sight 8000 series
- Cognex In-Sight 9000 series
- Cognex In-Sight Explorer
Weakness type
Related vulnerabilities
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-84841 — tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
- CVE-2026-84110 — Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security
- CVE-2026-73267 — Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check
- CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5
- CVE-2026-45274 — MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-73627 — JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass