CVE-2025-63210: Newtec CELOXA504 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.

Affected products

  • Newtec CELOXA504 Firmware: version celox-21.6.13 only
  • Newtec CELOXA820 Firmware: version celox-21.6.13 only

Published 2025-11-19. Last modified 2026-06-17.