CVE-2025-63210
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
19/11/2025
Last modified:
15/01/2026
Description
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the attacker can gain Superuser or Operator access without providing valid credentials.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:newtec:celoxa504_firmware:celox-21.6.13:*:*:*:*:*:*:* | ||
| cpe:2.3:h:newtec:celoxa504:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:newtec:celoxa820_firmware:celox-21.6.13:*:*:*:*:*:*:* | ||
| cpe:2.3:h:newtec:celoxa820:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



