CVE-2025-63205

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:bridgetech:vb220_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb220:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bridgetech:vb120_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb120:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:bridgetech:vb330_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb330:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:bridgetech:vb440_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb440:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:bridgetech:nomad_portable_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:nomad_portable:-:*:*:*:*:*:*:*

History

03 Feb 2026, 15:16

Type Values Removed Values Added
Summary (en) An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. (en) An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.

Information

Published : 2025-11-19 18:15

Updated : 2026-02-03 15:16


NVD link : CVE-2025-63205

Mitre link : CVE-2025-63205

CVE.ORG link : CVE-2025-63205


JSON object : View

Products Affected

bridgetech

  • vb120
  • vb440_firmware
  • vb330
  • vb330_firmware
  • vb120_firmware
  • vb440
  • vb220_firmware
  • vb220
  • nomad_portable_firmware
  • nomad_portable
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor