CVE-2025-52873HIGH 8.1EPSS p20.7%

CVE-2025-52873CVE-2025-52873

Description

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device properties (such as network settings), contradicting the security model proposed in the user manual.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS0.29% probability of exploitation · percentile 20.7% · 2026-06-19T12:03:05Z
Published2025-09-18
Last modified2026-04-15

Underlying weaknesses· 1

CWE-732

References

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-25-261-06

1

TypeTargetConfidenceTier
WeaknessIncorrect Permission Assignment for Critical Resourcecwe-7320%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-54497
CVE
CVE-2025-54818
CVE
CVE-2025-54810
CVE
CVE-2025-53969
CVE
CVE-2025-54754
CVE
CVE-2025-28202
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.