Vulnerability Description
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magewell | Pro Convert Hdmi 4K Plus Firmware | 1.2.213 |
| Magewell | Pro Convert Hdmi 4K Plus | - |
| Magewell | Pro Convert Hdmi Plus Firmware | 1.2.213 |
| Magewell | Pro Convert Hdmi Plus | - |
| Magewell | Pro Convert Hdmi Tx Firmware | 1.2.213 |
| Magewell | Pro Convert Hdmi Tx | - |
| Magewell | Pro Convert 12G Sdi 4K Plus Firmware | 1.2.213 |
| Magewell | Pro Convert 12G Sdi 4K Plus | - |
| Magewell | Pro Convert Sdi 4K Plus Firmware | 1.2.213 |
| Magewell | Pro Convert Sdi 4K Plus | - |
| Magewell | Pro Convert Sdi Plus Firmware | 1.2.213 |
| Magewell | Pro Convert Sdi Plus | - |
| Magewell | Pro Convert Sdi Tx Firmware | 1.2.213 |
| Magewell | Pro Convert Sdi Tx | - |
| Magewell | Pro Convert For Ndi To Hdmi Firmware | 1.2.213 |
| Magewell | Pro Convert For Ndi To Hdmi | - |
| Magewell | Pro Convert For Ndi To Hdmi 4K Firmware | 1.2.213 |
| Magewell | Pro Convert For Ndi To Hdmi 4K | - |
| Magewell | Pro Convert For Ndi To Aio Firmware | 1.2.213 |
| Magewell | Pro Convert For Ndi To Aio | - |
Related Weaknesses (CWE)
References
- https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63952ExploitThird Party Advisory
- https://www.magewell.comVendor Advisory
FAQ
What is CVE-2025-63952?
CVE-2025-63952 is a vulnerability with a CVSS score of 5.7 (MEDIUM). A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
How severe is CVE-2025-63952?
CVE-2025-63952 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63952?
Check the references section above for vendor advisories and patch information. Affected products include: Magewell Pro Convert Hdmi 4K Plus Firmware, Magewell Pro Convert Hdmi 4K Plus, Magewell Pro Convert Hdmi Plus Firmware, Magewell Pro Convert Hdmi Plus, Magewell Pro Convert Hdmi Tx Firmware.