CVE-2025-63205

7.5

Bridge Technologies · VB220, VB120, VB330, VB440, and NOMAD Probes

Bridge Technologies probes contain an information disclosure vulnerability in the password setup endpoint, allowing unauthenticated attackers to retrieve administrator credentials.

Executive summary

An unauthenticated information disclosure vulnerability in Bridge Technologies probe firmware allows attackers to obtain administrator passwords, posing a severe risk to network infrastructure security.

Vulnerability

The vulnerability exists in the /probe/core/setup/passwd endpoint, which permits unauthenticated remote attackers to access sensitive configuration data, specifically administrator credentials.

Business impact

Successful exploitation of this flaw grants an attacker full administrative control over the affected network probes. Given the CVSS score of 7.5, this high-severity vulnerability could lead to total compromise of monitoring traffic, unauthorized network reconnaissance, or the interception of sensitive production data, resulting in significant operational disruption and loss of confidentiality.

Remediation

Immediate Action: Update all affected probe firmware to version 5.6.0-4 or later, as these versions contain the necessary security fixes to remediate the exposure.

Proactive Monitoring: Review access logs for any unauthorized requests directed at the /probe/core/setup/passwd path and monitor for unusual administrative login activity.

Compensating Controls: Implement strict network segmentation and restrict access to the web management interfaces of these probes to trusted management IP addresses only via firewall rules.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the security researcher's technical write-up.

Analyst recommendation

The risk posed by this vulnerability is significant due to the nature of the exposed data. Organizations utilizing Bridge Technologies probe hardware must prioritize firmware updates to version 5.6.0-4 or later immediately. If an update cannot be performed during the current maintenance window, ensure that the management interface is not exposed to the public internet or untrusted network segments.

More Bridge Technologies CVEs

Sources