Medium severity6.5NVD Advisory· Published Nov 24, 2025· Updated Jun 17, 2026
CVE-2025-63953
CVE-2025-63953
Description
A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:magewell:ultra_encode_aio_firmware:2.3.206:*:*:*:*:*:*:*
- cpe:2.3:o:magewell:ultra_encode_hdmi_firmware:2.3.206:*:*:*:*:*:*:*
- cpe:2.3:o:magewell:ultra_encode_hdmi_plus_firmware:2.3.206:*:*:*:*:*:*:*
- cpe:2.3:o:magewell:ultra_encode_sdi_firmware:2.3.206:*:*:*:*:*:*:*
- cpe:2.3:o:magewell:ultra_encode_sdi_plus_firmware:2.3.206:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =1.2.213
Patches
Vulnerability mechanics
References
2- github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-63953nvdExploitMitigationThird Party Advisory
- www.magewell.comnvdProduct
News mentions
0No linked articles in our index yet.