CVE-2025-63205 Details
Description
An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.
A vulnerability allowing unauthorized access to sensitive information, such as administrator passwords, has been identified in Bridge Technologies probes, including the VB220 IP Network Probe, VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD. This issue affects firmware versions 6.5.0-9 and arises from improper authorization, allowing attackers to exploit the /probe/core/setup/passwd endpoint to retrieve password data.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure | CISA-ADP | ExploitThird Party Advisory |
| https://bridgetech.tv/ | [email protected] | Product |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| bridgetech vb220 firmware | 6.5.0-9 |
CPE
Remediation
| |
| bridgetech vb220 | All versions |
CPE
Remediation
| |
| bridgetech vb120 firmware | 6.5.0-9 |
CPE
Remediation
| |
| bridgetech vb120 | All versions |
CPE
Remediation
| |
| bridgetech vb330 firmware | 6.5.0-9 |
CPE
Remediation
| |
| bridgetech vb330 | All versions |
CPE
Remediation
| |
| bridgetech vb440 firmware | 6.5.0-9 |
CPE
Remediation
| |
| bridgetech vb440 | All versions |
CPE
Remediation
| |
| bridgetech nomad portable firmware | 6.5.0-9 |
CPE
Remediation
| |
| bridgetech nomad portable | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | CVE Modified | [email protected] |
| Jan 15, 2026 | Initial Analysis | [email protected] |
| Nov 20, 2025 | CVE Modified | CISA-ADP |
| Nov 19, 2025 | New CVE Received | [email protected] |