ZeroHour

CVE-2025-63952

PoC
CVSS 3.1
5.7 medium
EPSS
<1%p5
Published
()
Modified
Description

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Vendors
magewell
Products
pro convert hdmi 4k plus firmware, pro convert hdmi plus firmware, pro convert hdmi tx firmware, pro convert 12g sdi 4k plus firmware, pro convert sdi 4k plus firmware, pro convert sdi plus firmware, pro convert sdi tx firmware, pro convert for ndi to hdmi firmware, pro convert for ndi to hdmi 4k firmware, pro convert for ndi to aio firmware, pro convert for ndi to sdi firmware, pro convert aes67 firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.