Vulnerability Description
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Newtec | Celoxa504 Firmware | celox-21.6.13 |
| Newtec | Celoxa504 | - |
| Newtec | Celoxa820 Firmware | celox-21.6.13 |
| Newtec | Celoxa820 | - |
Related Weaknesses (CWE)
References
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6321ExploitThird Party Advisory
- https://www.newtec.com/Product
FAQ
What is CVE-2025-63210?
CVE-2025-63210 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted respon...
How severe is CVE-2025-63210?
CVE-2025-63210 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63210?
Check the references section above for vendor advisories and patch information. Affected products include: Newtec Celoxa504 Firmware, Newtec Celoxa504, Newtec Celoxa820 Firmware, Newtec Celoxa820.