Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32583 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink Mobile Application 1.40.41, and YoLink MQTT Broker. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yosmart
Yosmart yolink Hub Yosmart yolink Mobile Application Yosmart yolink Mqtt Broker |
|
| Vendors & Products |
Yosmart
Yosmart yolink Hub Yosmart yolink Mobile Application Yosmart yolink Mqtt Broker |
Mon, 06 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink Mobile Application 1.40.41, and YoLink MQTT Broker. | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-06T20:14:14.598Z
Reserved: 2025-09-16T00:00:00.000Z
Link: CVE-2025-59448
Updated: 2025-10-06T20:14:07.877Z
Status : Awaiting Analysis
Published: 2025-10-06T20:15:36.210
Modified: 2025-10-08T19:38:32.610
Link: CVE-2025-59448
No data.
OpenCVE Enrichment
Updated: 2025-10-08T13:39:37Z
EUVD