CVE-2025-63952
PoC —CVSS 3.1
5.7 medium
EPSS
<1%p5
Published
()
Modified
Description
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
- Vendors
- magewell
- Products
- pro convert hdmi 4k plus firmware, pro convert hdmi plus firmware, pro convert hdmi tx firmware, pro convert 12g sdi 4k plus firmware, pro convert sdi 4k plus firmware, pro convert sdi plus firmware, pro convert sdi tx firmware, pro convert for ndi to hdmi firmware, pro convert for ndi to hdmi 4k firmware, pro convert for ndi to aio firmware, pro convert for ndi to sdi firmware, pro convert aes67 firmware
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.