CVE-2025-63952

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
References
Link Resource
https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 Exploit Third Party Advisory
https://www.magewell.com Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:magewell:pro_convert_hdmi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_4k_plus:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:magewell:pro_convert_hdmi_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_plus:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:magewell:pro_convert_hdmi_tx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_tx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:magewell:pro_convert_12g_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_12g_sdi_4k_plus:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:magewell:pro_convert_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_sdi_4k_plus:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:magewell:pro_convert_sdi_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_sdi_plus:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:magewell:pro_convert_sdi_tx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_sdi_tx:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_4k_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi_4k:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:magewell:pro_convert_for_ndi_to_aio_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_aio:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:magewell:pro_convert_for_ndi_to_sdi_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_sdi:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:magewell:pro_convert_aes67_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_aes67:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:magewell:pro_convert_audio_dx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_audio_dx:-:*:*:*:*:*:*:*

History

30 Dec 2025, 18:13

Type Values Removed Values Added
References () https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 - () https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 - Exploit, Third Party Advisory
References () https://www.magewell.com - () https://www.magewell.com - Vendor Advisory
First Time Magewell pro Convert For Ndi To Sdi
Magewell pro Convert For Ndi To Aio Firmware
Magewell pro Convert Sdi Plus Firmware
Magewell pro Convert Audio Dx Firmware
Magewell pro Convert Audio Dx
Magewell pro Convert Hdmi 4k Plus
Magewell pro Convert 12g Sdi 4k Plus Firmware
Magewell
Magewell pro Convert Hdmi Plus
Magewell pro Convert For Ndi To Hdmi
Magewell pro Convert For Ndi To Sdi Firmware
Magewell pro Convert Hdmi Plus Firmware
Magewell pro Convert Sdi 4k Plus
Magewell pro Convert For Ndi To Hdmi 4k
Magewell pro Convert Sdi Tx
Magewell pro Convert Aes67 Firmware
Magewell pro Convert 12g Sdi 4k Plus
Magewell pro Convert Sdi Plus
Magewell pro Convert Hdmi Tx
Magewell pro Convert Sdi 4k Plus Firmware
Magewell pro Convert Sdi Tx Firmware
Magewell pro Convert For Ndi To Hdmi 4k Firmware
Magewell pro Convert Aes67
Magewell pro Convert Hdmi 4k Plus Firmware
Magewell pro Convert Hdmi Tx Firmware
Magewell pro Convert For Ndi To Hdmi Firmware
Magewell pro Convert For Ndi To Aio
CPE cpe:2.3:h:magewell:pro_convert_sdi_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_hdmi_tx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_sdi_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_4k_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_for_ndi_to_aio_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_sdi_tx:-:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi_4k:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_hdmi_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_audio_dx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_tx:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_12g_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_aes67_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_aes67:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_for_ndi_to_sdi_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_hdmi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_aio:-:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_for_ndi_to_sdi:-:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_audio_dx:-:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_12g_sdi_4k_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_hdmi_4k_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:magewell:pro_convert_sdi_tx_firmware:1.2.213:*:*:*:*:*:*:*
cpe:2.3:h:magewell:pro_convert_sdi_4k_plus:-:*:*:*:*:*:*:*

24 Nov 2025, 19:15

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7

24 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 17:16

Updated : 2025-12-30 18:13


NVD link : CVE-2025-63952

Mitre link : CVE-2025-63952

CVE.ORG link : CVE-2025-63952


JSON object : View

Products Affected

magewell

  • pro_convert_hdmi_4k_plus_firmware
  • pro_convert_sdi_4k_plus
  • pro_convert_for_ndi_to_hdmi
  • pro_convert_for_ndi_to_hdmi_firmware
  • pro_convert_hdmi_plus_firmware
  • pro_convert_sdi_4k_plus_firmware
  • pro_convert_aes67
  • pro_convert_hdmi_4k_plus
  • pro_convert_sdi_tx_firmware
  • pro_convert_for_ndi_to_aio
  • pro_convert_for_ndi_to_hdmi_4k_firmware
  • pro_convert_for_ndi_to_sdi_firmware
  • pro_convert_12g_sdi_4k_plus
  • pro_convert_for_ndi_to_hdmi_4k
  • pro_convert_aes67_firmware
  • pro_convert_sdi_plus
  • pro_convert_hdmi_plus
  • pro_convert_hdmi_tx_firmware
  • pro_convert_sdi_tx
  • pro_convert_12g_sdi_4k_plus_firmware
  • pro_convert_audio_dx
  • pro_convert_for_ndi_to_sdi
  • pro_convert_sdi_plus_firmware
  • pro_convert_for_ndi_to_aio_firmware
  • pro_convert_audio_dx_firmware
  • pro_convert_hdmi_tx
CWE
CWE-352

Cross-Site Request Forgery (CSRF)