CVE-2025-63952

MEDIUMCVSS 5.7/10EPSS 0.14%

Last modified

CVE-2025-63952 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.

Description

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Metrics

CVSS 3.1
5.7/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

EPSS Probability
0.14%

3.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MagewellPro Convert Hdmi 4k Plus Firmware1.2.213
MagewellPro Convert Hdmi Plus Firmware1.2.213
MagewellPro Convert Hdmi Tx Firmware1.2.213
MagewellPro Convert 12g Sdi 4k Plus Firmware1.2.213
MagewellPro Convert Sdi 4k Plus Firmware1.2.213
MagewellPro Convert Sdi Plus Firmware1.2.213
MagewellPro Convert Sdi Tx Firmware1.2.213
MagewellPro Convert For Ndi To Hdmi Firmware1.2.213
MagewellPro Convert For Ndi To Hdmi 4k Firmware1.2.213
MagewellPro Convert For Ndi To Aio Firmware1.2.213
MagewellPro Convert For Ndi To Sdi Firmware1.2.213
MagewellPro Convert Aes67 Firmware1.2.213
MagewellPro Convert Audio Dx Firmware1.2.213

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-63952?
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
How severe is CVE-2025-63952?
CVE-2025-63952 has a CVSS score of 5.7/10 (MEDIUM severity). The EPSS model estimates a 0.14% probability of exploitation in the next 30 days.
How do I fix CVE-2025-63952?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-63952?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST