CVE-2025-63208
7.5Bridge Technologies · VB288 Objective QoE Content Extractor
A vulnerability in Bridge Technologies VB288 firmware allows unauthenticated attackers to retrieve sensitive information, including administrator passwords, via a specific API endpoint.
Executive summary
An unauthenticated information disclosure vulnerability in Bridge Technologies VB288 firmware poses a critical risk of credential theft and unauthorized administrative access.
Vulnerability
The vulnerability exists in the /probe/core/setup/passwd endpoint, which fails to enforce authentication, allowing any unauthenticated remote attacker to access sensitive configuration data.
Business impact
The compromise of administrator credentials provides attackers with full control over the device, facilitating unauthorized monitoring or disruption of network quality analysis. With a CVSS score of 7.5, this high severity flaw could lead to complete loss of confidentiality regarding system administrative accounts and potential pivoting into critical infrastructure segments.
Remediation
Immediate Action: Restrict network access to the management interface of the VB288 device using an isolated management VLAN or firewall rules until a vendor-supplied patch is applied.
Proactive Monitoring: Review web server access logs for any requests directed toward the /probe/core/setup/passwd path, as these are highly indicative of exploitation attempts.
Compensating Controls: Implement a Web Application Firewall (WAF) or an application-layer proxy to block all unauthorized requests to the identified vulnerable endpoint.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the research write-up referenced in the CVE record.
Analyst recommendation
Given the exposure of administrative credentials, immediate network-level isolation is required to prevent unauthorized access. Organizations should contact Bridge Technologies for the latest firmware updates and apply them as soon as they become available to remediate this critical information disclosure flaw.