CVE-2025-59449

MEDIUM

YoSmart YoLink MQTT broker <2025-10-02 - SSRF

Title source: llm
STIX 2.1

Description

The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices.

Scores

CVSS v3 4.9
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
YoSmart/YoLink MQTT broker < 2025-10-02
Published Oct 06, 2025
Tracked Since Feb 18, 2026