CVE-2025-63210

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.
Configurations

No configuration.

History

19 Nov 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-303
CWE-302
CWE-287

19 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 18:15

Updated : 2025-11-19 19:15


NVD link : CVE-2025-63210

Mitre link : CVE-2025-63210

CVE.ORG link : CVE-2025-63210


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-302

Authentication Bypass by Assumed-Immutable Data

CWE-303

Incorrect Implementation of Authentication Algorithm