A
Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
References
| Link | Resource |
|---|---|
| https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63953 | Exploit Third Party Advisory Mitigation |
| https://www.magewell.com | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
History
30 Dec 2025, 17:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:magewell:ultra_encode_sdi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_hdmi:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_hdmi_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_hdmi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_sdi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_aio:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_sdi_plus_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_sdi_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_aio_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_hdmi_plus_firmware:2.3.206:*:*:*:*:*:*:* |
|
| References | () https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63953 - Exploit, Third Party Advisory, Mitigation | |
| References | () https://www.magewell.com - Product | |
| First Time |
Magewell ultra Encode Hdmi Plus
Magewell ultra Encode Sdi Plus Magewell ultra Encode Hdmi Firmware Magewell ultra Encode Sdi Magewell ultra Encode Aio Firmware Magewell ultra Encode Hdmi Magewell Magewell ultra Encode Sdi Firmware Magewell ultra Encode Hdmi Plus Firmware Magewell ultra Encode Aio Magewell ultra Encode Sdi Plus Firmware |
24 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-352 |
24 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 17:16
Updated : 2025-12-30 17:58
NVD link : CVE-2025-63953
Mitre link : CVE-2025-63953
CVE.ORG link : CVE-2025-63953
JSON object : View
Products Affected
CWE
CWE-352
Cross-Site Request Forgery (CSRF)