CVE-2025-63208: Bridgetech VB288 Firmware

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

Affected products

Published 2025-11-19. Last modified 2026-06-17.