CVE-2025-63952

MEDIUM
Published Nov 24, 2025 Modified Dec 30, 2025 CWE-352

Description

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Is your site exposed to CVE-2025-63952?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.7
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

Weakness Type (CWE)

CWE-352 Cross-Site Request Forgery

Affected Products

Vendor Product
magewell pro_convert_hdmi_4k_plus_firmware
magewell pro_convert_hdmi_4k_plus
magewell pro_convert_hdmi_plus_firmware
magewell pro_convert_hdmi_plus
magewell pro_convert_hdmi_tx_firmware
magewell pro_convert_hdmi_tx
magewell pro_convert_12g_sdi_4k_plus_firmware
magewell pro_convert_12g_sdi_4k_plus
magewell pro_convert_sdi_4k_plus_firmware
magewell pro_convert_sdi_4k_plus
magewell pro_convert_sdi_plus_firmware
magewell pro_convert_sdi_plus
magewell pro_convert_sdi_tx_firmware
magewell pro_convert_sdi_tx
magewell pro_convert_for_ndi_to_hdmi_firmware
magewell pro_convert_for_ndi_to_hdmi
magewell pro_convert_for_ndi_to_hdmi_4k_firmware
magewell pro_convert_for_ndi_to_hdmi_4k
magewell pro_convert_for_ndi_to_aio_firmware
magewell pro_convert_for_ndi_to_aio
magewell pro_convert_for_ndi_to_sdi_firmware
magewell pro_convert_for_ndi_to_sdi
magewell pro_convert_aes67_firmware
magewell pro_convert_aes67
magewell pro_convert_audio_dx_firmware
magewell pro_convert_audio_dx

References

Frequently Asked Questions

What is CVE-2025-63952? +
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request. It has a CVSS v3.1 base score of 5.7 (MEDIUM).
How severe is CVE-2025-63952? +
CVE-2025-63952 has a CVSS v3.1 score of 5.7 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-63952? +
CVE-2025-63952 affects products from magewell, specifically: pro_convert_12g_sdi_4k_plus, pro_convert_12g_sdi_4k_plus_firmware, pro_convert_aes67, pro_convert_aes67_firmware, pro_convert_audio_dx, pro_convert_audio_dx_firmware, pro_convert_for_ndi_to_aio, pro_convert_for_ndi_to_aio_firmware, pro_convert_for_ndi_to_hdmi, pro_convert_for_ndi_to_hdmi_4k, pro_convert_for_ndi_to_hdmi_4k_firmware, pro_convert_for_ndi_to_hdmi_firmware, pro_convert_for_ndi_to_sdi, pro_convert_for_ndi_to_sdi_firmware, pro_convert_hdmi_4k_plus, pro_convert_hdmi_4k_plus_firmware, pro_convert_hdmi_plus, pro_convert_hdmi_plus_firmware, pro_convert_hdmi_tx, pro_convert_hdmi_tx_firmware, pro_convert_sdi_4k_plus, pro_convert_sdi_4k_plus_firmware, pro_convert_sdi_plus, pro_convert_sdi_plus_firmware, pro_convert_sdi_tx, pro_convert_sdi_tx_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-63952? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-63952 — free, no signup required.