CVE-2025-63214: bridgetech VBC Server & Element Manager Broken Access Control Vulnerability Description An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10, 6.5.0-9, allowing unauthorized attackers to delete and create arbitrary accounts. Vendor Information Vendor: bridgetech Vendor Homepage: https://bridgetech.tv/ Affected Products Product: bridgetech VBC Server & Element Manager Build Version: Aug 12 2025, Jul 1 2025 12:43:42 Firmware Version: 6.5.0-10, 6.5.0-9 Vulnerable Endpoints /vbc/core/userSetupDoc/userSetupDoc Attack Type Type: Broken Access Control Classification: Improper Authorization Impact Severity: High Attack Vector Access Method: Remote, over HTTP Authentication Requirement: None (unauthenticated) Exploit Complexity: Low (simple HTTP requests) Proof of Concept (PoC) PoC Video [VBC_Server.mp4]