Historical intelligence backfill. This assessment covers reporting originally published on 2025-09-24 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Cognex In-Sight cameras shipped a hard-coded password and cleartext on the line

Nozomi 24 September 2025 / CISA ICSA-25-261-06 18 September — nine issues, CVSS 8.6 class, In-Sight 2000/7000/8000/9000 plus Explorer through 6.5.1. Adjacent, not a WAN worm. Still a vision-system on the cell network.

RWP Ventures · 2026-09-07 · event 2025-09-18 · 2 min read · priority 7.8

Bottom line up front

CONFIRMED Nozomi Labs 24 September 2025 on Cognex In-Sight Explorer 6.5.1 and IS2000M-120 firmware 6.5.1; CISA ICSA-25-261-06 18 September. Affected: In-Sight 2000/7000/8000/9000 firmware 5.x–6.5.1 and Explorer 5.x–6.5.1. Highlight CVEs: CVE-2025-54754 hard-coded password (CVSS 8.6 v4 / 8.0 v3.1) — adjacent unauth retrieve of a password that decrypts traffic; CVE-2025-47698 / 54818 cleartext; CVE-2025-54810 capture-replay; CVE-2025-53969 client-side enforcement; permission issues 54497/52873; 54860 auth-attempt restriction. Cognex: these Explorer-based systems are legacy; migrate to In-Sight Vision Suite (2800/3800/8900). In-the-wild: CISA-ADP exploitation none at listing. Process impact: ASSESSED if a vision camera is in the cell and an adjacent attacker is already on that LAN; not a confirmed outage.

Historical backfill of 24 September 2025 reporting; added 7 September 2026.

What happened

A vision camera and its Windows client failed basic crypto and auth hygiene. Adjacent attacker on the manufacturing VLAN is the model.

Why it mattered

Smart cameras sit next to robots. "Adjacent" is the cell, not the parking lot.

Who / what was affected

Cognex In-Sight 5.x/6.x trains through 6.5.1 worldwide manufacturing.

Technical context

Segment vision. Prefer the successor product line Cognex named. Do not leave Explorer 6.5.1 on an engineering laptop on the cell Wi-Fi.

Exploitation / threat status at the time

CONFIRMED nine CVEs, CISA advisory.

UNKNOWN exploitation.

What defenders should have done

  1. Firmware/Explorer past 6.5.1 or replace with Vision Suite.
  2. No In-Sight management on the same VLAN as the PLC if you can avoid it.
  3. Hunt hard-coded secrets in the client install.

RWP assessment

Confidence: High on the CISA/Nozomi table.

Defensive actions

  1. Manufacturing vision-system inventory.
  2. Adjacent-network assumption in the cell.
  3. Pair with Hanwha Wisenet — different vendor, same "camera on OT" class.

Sources

  1. Nozomi Networks Labs — Nine vulnerabilities in Cognex InSight IS2000M-120
  2. CISA — ICSA-25-261-06 Cognex In-Sight Explorer and camera firmware
  3. CVE-2025-54754 — Hard-coded password in In-Sight Explorer