PT-2025-47500 · Newtec · Celoxa504+2

Published

2025-11-19

·

Updated

2025-11-20

·

CVE-2025-63210

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Newtec Celox UHD versions celox-21.6.13
Description The Newtec Celox UHD (models CELOXA504, CELOXA820) is affected by an authentication bypass. An attacker can gain Superuser or Operator access without valid credentials by modifying intercepted responses from the /celoxservice endpoint during the loginWithUserName flow. This is achieved by injecting a forged response body.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /celoxservice endpoint.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-63210

Affected Products

Celoxa504
Celoxa820
Newtec Celox Uhd