CVE-2025-63952
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.1 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
Affected (13)
Products: Magewell: Pro Convert Hdmi 4k Plus Firmware, Pro Convert Hdmi Plus Firmware, Pro Convert Hdmi Tx Firmware, Pro Convert 12g Sdi 4k Plus Firmware, Pro Convert Sdi 4k Plus Firmware, Pro Convert Sdi Plus Firmware, Pro Convert Sdi Tx Firmware, Pro Convert For Ndi To Hdmi Firmware, Pro Convert For Ndi To Hdmi 4k Firmware, Pro Convert For Ndi To Aio Firmware, Pro Convert For Ndi To Sdi Firmware, Pro Convert Aes67 Firmware, Pro Convert Audio Dx Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Hdmi 4k Plus | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Hdmi Plus | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Hdmi Tx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert 12g Sdi 4k Plus | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Sdi 4k Plus | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Sdi Plus | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Sdi Tx | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert For Ndi To Hdmi | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert For Ndi To Hdmi 4k | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert For Ndi To Aio | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert For Ndi To Sdi | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Aes67 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.213 |
| Running on/with | Platform Versions |
|---|---|
Magewell Pro Convert Audio Dx | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.