CVE-2025-63205
An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.
Published:Nov 19, 2025
Last Modified:Feb 3, 2026
EPS:Nov 19, 2025
EPSS Score:0.00059
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Bridgetech
Product
Nomad
Bridgetech
Nomad
Vendor
Bridgetech
Product
Nomad Portable
Bridgetech
Nomad Portable
Vendor
Bridgetech
Product
Nomad Portable Firmware
Bridgetech
Nomad Portable Firmware
Vendor
Bridgetech
Product
Vb120
Bridgetech
Vb120
Vendor
Bridgetech
Product
Vb120 Firmware
Bridgetech
Vb120 Firmware
Vendor
Bridgetech
Product
Vb220
Bridgetech
Vb220
Vendor
Bridgetech
Product
Vb220 Firmware
Bridgetech
Vb220 Firmware
Vendor
Bridgetech
Product
Vb330
Bridgetech
Vb330
Vendor
Bridgetech
Product
Vb330 Firmware
Bridgetech
Vb330 Firmware
Vendor
Bridgetech
Product
Vb440
Bridgetech
Vb440
Vendor
Bridgetech
Product
Vb440 Firmware
Bridgetech
Vb440 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
