Get real-time updates on Telegram
CVE-2025-59448: YoLink ecosystem 0 through 2025-10-02
CVE-2025-59448. CVSS 3.1 base score 4.7 (MEDIUM, Vendor/CNA). EPSS 0.0018 (percentile 0.06902), scored 2026-10-08.
Affected technology
YoLink ecosystem · 0 through 2025-10-02
YoSmart
Description’s affected range: through 2025-10-02 leverage unencrypted MQTT to communicate over the internet
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Adjacent network · No privileges required · No user interaction required
What an attacker can do
An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. Vendor/CNA’s CVSS 3.1 assessment (base score 4.7/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-319
- CCR priority
- 18.8 /100 (P5)
- CVSS 3.1
- 4.7 /10 · CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N · Vendor/CNA
- EPSS
- 0.0018 · percentile 0.06902 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-59448.html