<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:50:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253090</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253090</link>
      <description>EUVD-2026-253090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253090</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54810</link>
      <description>&lt;p&gt;Cognex In-Sight Explorer and In-Sight Camera Firmware expose&lt;/p&gt;
&lt;p&gt;a proprietary protocol on TCP port 1069 to perform management operations
 such as modifying system properties. The user management functionality 
handles sensitive data such as registered usernames and passwords over 
an unencrypted channel, allowing an adjacent attacker to intercept valid
 credentials to gain access to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cognex In-Sight Explorer and In-Sight Camera Firmware expose&lt;/p&gt;
&lt;p&gt;a proprietary protocol on TCP port 1069 to perform management operations
 such as modifying system properties. The user management functionality 
handles sensitive data such as registered usernames and passwords over 
an unencrypted channel, allowing an adjacent attacker to intercept valid
 credentials to gain access to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54810</guid>
    </item>
    <item>
      <title>GHSA-cr6h-4367-m34r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cr6h-4367-m34r</link>
      <description>&lt;p&gt;Cognex In-Sight Explorer and In-Sight Camera Firmware expose&lt;/p&gt;
&lt;p&gt;a proprietary protocol on TCP port 1069 to perform management operations
 such as modifying system properties. The user management functionality 
handles sensitive data such as registered usernames and passwords over 
an unencrypted channel, allowing an adjacent attacker to intercept valid
 credentials to gain access to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cognex In-Sight Explorer and In-Sight Camera Firmware expose&lt;/p&gt;
&lt;p&gt;a proprietary protocol on TCP port 1069 to perform management operations
 such as modifying system properties. The user management functionality 
handles sensitive data such as registered usernames and passwords over 
an unencrypted channel, allowing an adjacent attacker to intercept valid
 credentials to gain access to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cr6h-4367-m34r</guid>
    </item>
    <item>
      <title>ICSA-25-261-06 — Cognex In-Sight Explorer and In-Sight Camera Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-261-06</link>
      <description>&lt;p&gt;An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device. An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure. A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data folder is created with very weak privileges, allowing any user logged into the Windows system to modify its content. The device exposes a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service causes a DoS attack, leaving the telnet service into an unreachable state. The device exposes a Telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device properties (such as network settings), contradicting the security model proposed in the user manual. The device exposes a Telnet-based service on port 23 to allow management operations s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device. An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure. A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data folder is created with very weak privileges, allowing any user logged into the Windows system to modify its content. The device exposes a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service causes a DoS attack, leaving the telnet service into an unreachable state. The device exposes a Telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device properties (such as network settings), contradicting the security model proposed in the user manual. The device exposes a Telnet-based service on port 23 to allow management operations s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-261-06</guid>
    </item>
  </channel>
</rss>
