A
Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
References
| Link | Resource |
|---|---|
| https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 | Exploit Third Party Advisory |
| https://www.magewell.com | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
History
30 Dec 2025, 18:13
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:magewell:pro_convert_sdi_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_sdi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_tx:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_12g_sdi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_aes67:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_tx:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_aio_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_tx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_12g_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_sdi:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_tx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_4k_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi_4k:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_audio_dx:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_aes67_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_aio:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_audio_dx_firmware:1.2.213:*:*:*:*:*:*:* |
|
| References | () https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 - Exploit, Third Party Advisory | |
| References | () https://www.magewell.com - Vendor Advisory | |
| First Time |
Magewell pro Convert Sdi Plus Firmware
Magewell pro Convert Sdi Tx Magewell pro Convert For Ndi To Aio Firmware Magewell pro Convert Hdmi 4k Plus Firmware Magewell pro Convert Audio Dx Magewell pro Convert For Ndi To Hdmi Firmware Magewell Magewell pro Convert For Ndi To Aio Magewell pro Convert For Ndi To Hdmi Magewell pro Convert Audio Dx Firmware Magewell pro Convert Hdmi Tx Firmware Magewell pro Convert Sdi 4k Plus Magewell pro Convert Sdi Tx Firmware Magewell pro Convert For Ndi To Hdmi 4k Magewell pro Convert Hdmi Plus Magewell pro Convert For Ndi To Sdi Firmware Magewell pro Convert Hdmi 4k Plus Magewell pro Convert Aes67 Magewell pro Convert For Ndi To Sdi Magewell pro Convert 12g Sdi 4k Plus Firmware Magewell pro Convert 12g Sdi 4k Plus Magewell pro Convert Hdmi Tx Magewell pro Convert For Ndi To Hdmi 4k Firmware Magewell pro Convert Aes67 Firmware Magewell pro Convert Sdi 4k Plus Firmware Magewell pro Convert Sdi Plus Magewell pro Convert Hdmi Plus Firmware |
24 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-352 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.7 |
24 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 17:16
Updated : 2025-12-30 18:13
NVD link : CVE-2025-63952
Mitre link : CVE-2025-63952
CVE.ORG link : CVE-2025-63952
JSON object : View
Products Affected
- pro_convert_sdi_4k_plus
- pro_convert_for_ndi_to_sdi
- pro_convert_sdi_plus_firmware
- pro_convert_12g_sdi_4k_plus_firmware
- pro_convert_aes67
- pro_convert_hdmi_plus
- pro_convert_sdi_plus
- pro_convert_sdi_tx_firmware
- pro_convert_for_ndi_to_hdmi_firmware
- pro_convert_for_ndi_to_hdmi
- pro_convert_for_ndi_to_aio
- pro_convert_hdmi_4k_plus_firmware
- pro_convert_hdmi_tx
- pro_convert_for_ndi_to_sdi_firmware
- pro_convert_aes67_firmware
- pro_convert_for_ndi_to_aio_firmware
- pro_convert_for_ndi_to_hdmi_4k_firmware
- pro_convert_12g_sdi_4k_plus
- pro_convert_for_ndi_to_hdmi_4k
- pro_convert_hdmi_4k_plus
- pro_convert_audio_dx
- pro_convert_hdmi_tx_firmware
- pro_convert_hdmi_plus_firmware
- pro_convert_sdi_4k_plus_firmware
- pro_convert_sdi_tx
- pro_convert_audio_dx_firmware
CWE
CWE-352
Cross-Site Request Forgery (CSRF)