CVE-2025-11998: HP Card Readers (B Models) – Potential Information Disclosure
The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inherited under certain conditions —e.g., when an NFC device (such as a smartphone/smartwatches) is in proximity during a card swipe event.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11998?
CVE-2025-11998 has been rated as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-11998?
To mitigate CVE-2025-11998, ensure that your HP Card Readers B Models are updated with the latest firmware and security patches from HP.
What types of devices are affected by CVE-2025-11998?
CVE-2025-11998 affects HP Card Readers B Models X3D03B and Y7C05B.
What kind of information can be disclosed due to CVE-2025-11998?
CVE-2025-11998 can potentially allow prior user identity to be inherited during specific conditions involving NFC devices.
Is there a risk if I use an NFC device with my HP Card Readers B Models concerning CVE-2025-11998?
Yes, using an NFC device in proximity during a card swipe event may expose user identity information as per CVE-2025-11998.