Home

Description

The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

PUBLISHED Reserved 2025-04-14 | Published 2025-12-05 | Updated 2025-12-05 | Assigner mitre




MEDIUM: 4.7CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-331 Insufficient Entropy

Product status

Default status
unaffected

Any version before 2025-04-18
affected

References

kdeconnect.kde.org

kde.org/info/security/advisory-20250418-3.txt

cve.org (CVE-2025-32898)

nvd.nist.gov (CVE-2025-32898)