CVE-2025-63953: Magewell Ultra Encode Aio Firmware

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Affected products

  • Magewell Ultra Encode Aio Firmware: version 2.3.206 only
  • Magewell Ultra Encode Hdmi Firmware: version 2.3.206 only
  • Magewell Ultra Encode Hdmi Plus Firmware: version 2.3.206 only
  • Magewell Ultra Encode Sdi Firmware: version 2.3.206 only
  • Magewell Ultra Encode Sdi Plus Firmware: version 2.3.206 only

Published 2025-11-24. Last modified 2026-06-17.