Magewell develops a focused line of audio and video conversion appliances—including Pro Convert products spanning HDMI, NDI, SDI, and audio interfaces—that serve professional broadcast and streaming environments. The observed vulnerability profile centers on cross-site request forgery weaknesses in the firmware of these networked converters, reflecting the web-management interfaces common to such devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magewell over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63953MEDIUM A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET reque | Nov 24, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-63952MEDIUM A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET reque | Nov 24, 2025 | 5.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magewell.
Media articles that mention a CVE ID that affects a product developed by Magewell — matched by CVE ID, not by vendor name.