CVE 5.8 MEDIUM

CVE-2025-59452_CVE-2025-59452

5.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Description

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

Basic Information

ID CVE-2025-59452
Source mitre
Published Oct 6, 2025 at 00:00
Modified Oct 6, 2025 at 20:16

Affected Product

Vendor YoSmart
Product YoLink API
Affected Versions YoSmart YoLink API 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.