Home

Description

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

PUBLISHED Reserved 2025-09-16 | Published 2025-10-06 | Updated 2025-10-06 | Assigner mitre




MEDIUM: 5.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-340 Generation of Predictable Numbers or Identifiers

Product status

Default status
unknown

Any version
affected

References

bishopfox.com/blog/advisories

shop.yosmart.com/pages/product-support

bishopfox.com/...20-smart-device-gave-me-access-to-your-home

cve.org (CVE-2025-59452)

nvd.nist.gov (CVE-2025-59452)

Download JSON