CVE-2025-11998 MEDIUM

CVE-2025-11998: HP Card Readers (B Models) – Potential Information Disclosure

Vendor Hp Inc.
Product Card Readers B Model
Weakness CWE-200 · Info exposure
Published October 30, 2025
Last update October 30, 2025

CVSS base score

6.8/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inherited under certain conditions —e.g., when an NFC device (such as a smartphone/smartwatches) is in proximity during a card swipe event.

Key dates

02Disclosure timeline

October 30, 2025 CVE published
October 30, 2025 Record updated