# CVE-2025-54810

## Summary

- **CVE ID:** CVE-2025-54810
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-294
- **Published:** Sep 18, 2025
- **Last Modified:** Mar 12, 2026

## Description

Cognex In-Sight Explorer and In-Sight Camera Firmware expose 

a proprietary protocol on TCP port 1069 to perform management operations
 such as modifying system properties. The user management functionality 
handles sensitive data such as registered usernames and passwords over 
an unencrypted channel, allowing an adjacent attacker to intercept valid
 credentials to gain access to the device.

## Affected Products

- Cognex — In-Sight 2000 series (5.x)
- Cognex — In-Sight 7000 series (5.x)
- Cognex — In-Sight 8000 series (5.x)
- Cognex — In-Sight 9000 series (5.x)
- Cognex — In-Sight Explorer (5.x)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-25-261-06)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._