A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magewell pro Convert 12g Sdi 4k Plus
Magewell pro Convert 12g Sdi 4k Plus Firmware Magewell pro Convert Aes67 Magewell pro Convert Aes67 Firmware Magewell pro Convert Audio Dx Magewell pro Convert Audio Dx Firmware Magewell pro Convert For Ndi To Aio Magewell pro Convert For Ndi To Aio Firmware Magewell pro Convert For Ndi To Hdmi Magewell pro Convert For Ndi To Hdmi 4k Magewell pro Convert For Ndi To Hdmi 4k Firmware Magewell pro Convert For Ndi To Hdmi Firmware Magewell pro Convert For Ndi To Sdi Magewell pro Convert For Ndi To Sdi Firmware Magewell pro Convert Hdmi 4k Plus Magewell pro Convert Hdmi 4k Plus Firmware Magewell pro Convert Hdmi Plus Magewell pro Convert Hdmi Plus Firmware Magewell pro Convert Hdmi Tx Magewell pro Convert Hdmi Tx Firmware Magewell pro Convert Sdi 4k Plus Magewell pro Convert Sdi 4k Plus Firmware Magewell pro Convert Sdi Plus Magewell pro Convert Sdi Plus Firmware Magewell pro Convert Sdi Tx Magewell pro Convert Sdi Tx Firmware |
|
| CPEs | cpe:2.3:h:magewell:pro_convert_12g_sdi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_aes67:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_audio_dx:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_aio:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_hdmi_4k:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_for_ndi_to_sdi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_hdmi_tx:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_4k_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:pro_convert_sdi_tx:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_12g_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_aes67_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_audio_dx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_aio_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_4k_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_hdmi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_for_ndi_to_sdi_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_hdmi_tx_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_4k_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_plus_firmware:1.2.213:*:*:*:*:*:*:* cpe:2.3:o:magewell:pro_convert_sdi_tx_firmware:1.2.213:*:*:*:*:*:*:* |
|
| Vendors & Products |
Magewell pro Convert 12g Sdi 4k Plus
Magewell pro Convert 12g Sdi 4k Plus Firmware Magewell pro Convert Aes67 Magewell pro Convert Aes67 Firmware Magewell pro Convert Audio Dx Magewell pro Convert Audio Dx Firmware Magewell pro Convert For Ndi To Aio Magewell pro Convert For Ndi To Aio Firmware Magewell pro Convert For Ndi To Hdmi Magewell pro Convert For Ndi To Hdmi 4k Magewell pro Convert For Ndi To Hdmi 4k Firmware Magewell pro Convert For Ndi To Hdmi Firmware Magewell pro Convert For Ndi To Sdi Magewell pro Convert For Ndi To Sdi Firmware Magewell pro Convert Hdmi 4k Plus Magewell pro Convert Hdmi 4k Plus Firmware Magewell pro Convert Hdmi Plus Magewell pro Convert Hdmi Plus Firmware Magewell pro Convert Hdmi Tx Magewell pro Convert Hdmi Tx Firmware Magewell pro Convert Sdi 4k Plus Magewell pro Convert Sdi 4k Plus Firmware Magewell pro Convert Sdi Plus Magewell pro Convert Sdi Plus Firmware Magewell pro Convert Sdi Tx Magewell pro Convert Sdi Tx Firmware |
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magewell
Magewell convert |
|
| Vendors & Products |
Magewell
Magewell convert |
Mon, 24 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-24T19:04:38.235Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63952
Updated: 2025-11-24T19:04:26.971Z
Status : Analyzed
Published: 2025-11-24T17:16:08.517
Modified: 2025-12-30T18:13:43.463
Link: CVE-2025-63952
No data.
OpenCVE Enrichment
Updated: 2025-11-26T11:11:07Z