Vulnerability Details CVE-2025-63211
Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5.0-10, allows attackers to execute arbitrary code via the addName parameter to the /vbc/core/userSetupDoc/userSetupDoc endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.0%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-63211
-
cpe:2.3:a:bridgetech:vbc_server:6.5.0-10
-
cpe:2.3:a:bridgetech:vbc_server:6.5.0-9