CVE-2025-63210: Newtec CELOXA504 Firmware
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.
Affected products
- Newtec CELOXA504 Firmware: version celox-21.6.13 only
- Newtec CELOXA820 Firmware: version celox-21.6.13 only
Published 2025-11-19. Last modified 2026-06-17.