« Volver al listado

CVE-2025-59452

Estado: AplazadaMedia (5.8)—

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-59452",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-59452",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-06T20:16:45.320859Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "YoSmart",
          "product": "YoLink API",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025-10-02"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-10-06T20:15:36.937",
  "references": [
    {
      "url": "https://bishopfox.com/blog/advisories",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bishopfox.com/blog/how-a-20-smart-device-gave-me-access-to-your-home",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://shop.yosmart.com/pages/product-support",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://shop.yosmart.com/pages/sa-2025-001",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-340"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50."
    },
    {
      "lang": "es",
      "value": "La API de YoSmart YoLink hasta el 02-10-2025 utiliza una URL de endpoint que se deriva de la dirección MAC de un dispositivo junto con un hash MD5 de información no secreta, como una clave que comienza con cf50."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "sourceIdentifier": "cve@mitre.org"
}