The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Yosmart
Yosmart yolink Mqtt Broker |
|
Vendors & Products |
Yosmart
Yosmart yolink Mqtt Broker |
Mon, 06 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 06 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices. | The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices. |
Mon, 06 Oct 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices. | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-10-06T00:00:00.000Z
Updated: 2025-10-06T20:12:10.296Z
Reserved: 2025-09-16T00:00:00.000Z
Link: CVE-2025-59449

Updated: 2025-10-06T20:12:05.230Z

Status : Received
Published: 2025-10-06T20:15:36.403
Modified: 2025-10-06T20:15:36.403
Link: CVE-2025-59449

No data.