The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.
References
| Link | Resource |
|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63210_Newtec%20Celox%20UHD%20Authentication%20Bypass%20_%20Privilege%20Escalation | Exploit Third Party Advisory |
| https://www.newtec.com/ | Product |
Configurations
History
15 Jan 2026, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Newtec celoxa820
Newtec Newtec celoxa504 Newtec celoxa504 Firmware Newtec celoxa820 Firmware |
|
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63210_Newtec%20Celox%20UHD%20Authentication%20Bypass%20_%20Privilege%20Escalation - Exploit, Third Party Advisory | |
| References | () https://www.newtec.com/ - Product | |
| CPE | cpe:2.3:o:newtec:celoxa504_firmware:celox-21.6.13:*:*:*:*:*:*:* cpe:2.3:h:newtec:celoxa504:-:*:*:*:*:*:*:* cpe:2.3:h:newtec:celoxa820:-:*:*:*:*:*:*:* cpe:2.3:o:newtec:celoxa820_firmware:celox-21.6.13:*:*:*:*:*:*:* |
19 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 CWE-302 CWE-303 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2026-01-15 19:56
NVD link : CVE-2025-63210
Mitre link : CVE-2025-63210
CVE.ORG link : CVE-2025-63210
JSON object : View
Products Affected
newtec
- celoxa820
- celoxa504
- celoxa820_firmware
- celoxa504_firmware
