CVE-2025-63205

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:bridgetech:vb220_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb220:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bridgetech:vb120_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb120:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:bridgetech:vb330_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb330:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:bridgetech:vb440_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb440:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:bridgetech:nomad_portable_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:nomad_portable:-:*:*:*:*:*:*:*

History

15 Jan 2026, 19:47

Type Values Removed Values Added
CPE cpe:2.3:h:bridgetech:vb440:-:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:nomad_portable:-:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb220:-:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb330:-:*:*:*:*:*:*:*
cpe:2.3:h:bridgetech:vb120:-:*:*:*:*:*:*:*
cpe:2.3:o:bridgetech:nomad_portable_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:o:bridgetech:vb120_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:o:bridgetech:vb330_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:o:bridgetech:vb440_firmware:6.5.0-9:*:*:*:*:*:*:*
cpe:2.3:o:bridgetech:vb220_firmware:6.5.0-9:*:*:*:*:*:*:*
First Time Bridgetech vb440
Bridgetech nomad Portable Firmware
Bridgetech vb220
Bridgetech nomad Portable
Bridgetech vb120 Firmware
Bridgetech vb330 Firmware
Bridgetech vb220 Firmware
Bridgetech vb120
Bridgetech vb440 Firmware
Bridgetech vb330
Bridgetech
References () https://bridgetech.tv/ - () https://bridgetech.tv/ - Product
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure - Exploit, Third Party Advisory

20 Nov 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63205_bridgetech%20probes%20Information%20Disclosure -

19 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 18:15

Updated : 2026-01-15 19:47


NVD link : CVE-2025-63205

Mitre link : CVE-2025-63205

CVE.ORG link : CVE-2025-63205


JSON object : View

Products Affected

bridgetech

  • vb440_firmware
  • vb220_firmware
  • vb120
  • vb440
  • nomad_portable
  • nomad_portable_firmware
  • vb220
  • vb120_firmware
  • vb330
  • vb330_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor