CVE-2025-59452
Estado: AplazadaMedia (5.8)—
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-340
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-59452",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-59452",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-10-06T20:16:45.320859Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "YoSmart",
"product": "YoLink API",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2025-10-02"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-10-06T20:15:36.937",
"references": [
{
"url": "https://bishopfox.com/blog/advisories",
"source": "cve@mitre.org"
},
{
"url": "https://bishopfox.com/blog/how-a-20-smart-device-gave-me-access-to-your-home",
"source": "cve@mitre.org"
},
{
"url": "https://shop.yosmart.com/pages/product-support",
"source": "cve@mitre.org"
},
{
"url": "https://shop.yosmart.com/pages/sa-2025-001",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-340"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50."
},
{
"lang": "es",
"value": "La API de YoSmart YoLink hasta el 02-10-2025 utiliza una URL de endpoint que se deriva de la dirección MAC de un dispositivo junto con un hash MD5 de información no secreta, como una clave que comienza con cf50."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "cve@mitre.org"
}