PT-2025-47500 · Newtec · Celoxa504+2
Published
2025-11-19
·
Updated
2025-11-20
·
CVE-2025-63210
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Newtec Celox UHD versions celox-21.6.13
Description
The Newtec Celox UHD (models CELOXA504, CELOXA820) is affected by an authentication bypass. An attacker can gain Superuser or Operator access without valid credentials by modifying intercepted responses from the
/celoxservice endpoint during the loginWithUserName flow. This is achieved by injecting a forged response body.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
/celoxservice endpoint.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Celoxa504
Celoxa820
Newtec Celox Uhd