Home

Description

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

PUBLISHED Reserved 2025-04-14 | Published 2025-12-05 | Updated 2025-12-05 | Assigner mitre




MEDIUM: 4.3CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-348 Use of Less Trusted Source

Product status

Default status
unaffected

Any version before 2025-04-18
affected

References

kdeconnect.kde.org

kde.org/info/security/advisory-20250418-2.txt

cve.org (CVE-2025-32900)

nvd.nist.gov (CVE-2025-32900)