A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
References
| Link | Resource |
|---|---|
| https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 | Exploit Third Party Advisory |
| https://www.magewell.com | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
History
30 Dec 2025, 18:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952 - Exploit, Third Party Advisory | |
| References | () https://www.magewell.com - Vendor Advisory | |
| First Time |
Magewell pro Convert For Ndi To Sdi
Magewell pro Convert For Ndi To Aio Firmware Magewell pro Convert Sdi Plus Firmware Magewell pro Convert Audio Dx Firmware Magewell pro Convert Audio Dx Magewell pro Convert Hdmi 4k Plus Magewell pro Convert 12g Sdi 4k Plus Firmware Magewell Magewell pro Convert Hdmi Plus Magewell pro Convert For Ndi To Hdmi Magewell pro Convert For Ndi To Sdi Firmware Magewell pro Convert Hdmi Plus Firmware Magewell pro Convert Sdi 4k Plus Magewell pro Convert For Ndi To Hdmi 4k Magewell pro Convert Sdi Tx Magewell pro Convert Aes67 Firmware Magewell pro Convert 12g Sdi 4k Plus Magewell pro Convert Sdi Plus Magewell pro Convert Hdmi Tx Magewell pro Convert Sdi 4k Plus Firmware Magewell pro Convert Sdi Tx Firmware Magewell pro Convert For Ndi To Hdmi 4k Firmware Magewell pro Convert Aes67 Magewell pro Convert Hdmi 4k Plus Firmware Magewell pro Convert Hdmi Tx Firmware Magewell pro Convert For Ndi To Hdmi Firmware Magewell pro Convert For Ndi To Aio |
|
| CPE | cpe:2.3:h:magewell:pro_convert_sdi_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_tx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_4k_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_aio_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_tx:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi_4k:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_audio_dx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_tx:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_12g_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_aes67_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_aes67:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_sdi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_aio:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_sdi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_audio_dx:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_12g_sdi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_tx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_4k_plus:-:*:*:*:*:*:*:* |
24 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-352 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.7 |
24 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 17:16
Updated : 2025-12-30 18:13
NVD link : CVE-2025-63952
Mitre link : CVE-2025-63952
CVE.ORG link : CVE-2025-63952
JSON object : View
Products Affected
magewell
- pro_convert_hdmi_4k_plus_firmware
- pro_convert_sdi_4k_plus
- pro_convert_for_ndi_to_hdmi
- pro_convert_for_ndi_to_hdmi_firmware
- pro_convert_hdmi_plus_firmware
- pro_convert_sdi_4k_plus_firmware
- pro_convert_aes67
- pro_convert_hdmi_4k_plus
- pro_convert_sdi_tx_firmware
- pro_convert_for_ndi_to_aio
- pro_convert_for_ndi_to_hdmi_4k_firmware
- pro_convert_for_ndi_to_sdi_firmware
- pro_convert_12g_sdi_4k_plus
- pro_convert_for_ndi_to_hdmi_4k
- pro_convert_aes67_firmware
- pro_convert_sdi_plus
- pro_convert_hdmi_plus
- pro_convert_hdmi_tx_firmware
- pro_convert_sdi_tx
- pro_convert_12g_sdi_4k_plus_firmware
- pro_convert_audio_dx
- pro_convert_for_ndi_to_sdi
- pro_convert_sdi_plus_firmware
- pro_convert_for_ndi_to_aio_firmware
- pro_convert_audio_dx_firmware
- pro_convert_hdmi_tx
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
