CVE-2025-63952

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
mitreCNA
---
---
CISA-ADPADP
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
magewellpro_convert_hdmi_4k_plus_firmware
1.2.213
magewellpro_convert_hdmi_plus_firmware
1.2.213
magewellpro_convert_hdmi_tx_firmware
1.2.213
magewellpro_convert_12g_sdi_4k_plus_firmware
1.2.213
magewellpro_convert_sdi_4k_plus_firmware
1.2.213
magewellpro_convert_sdi_plus_firmware
1.2.213
magewellpro_convert_sdi_tx_firmware
1.2.213
magewellpro_convert_for_ndi_to_hdmi_firmware
1.2.213
magewellpro_convert_for_ndi_to_hdmi_4k_firmware
1.2.213
magewellpro_convert_for_ndi_to_aio_firmware
1.2.213
magewellpro_convert_for_ndi_to_sdi_firmware
1.2.213
magewellpro_convert_aes67_firmware
1.2.213
magewellpro_convert_audio_dx_firmware
1.2.213
𝑥
= Vulnerable software versions