CVE-2025-59450 Details
Description
The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.
A vulnerability exists in the YoSmart YoLink Smart Hub firmware version 0382, where unencrypted data can be extracted and used to determine network access credentials. This flaw exposes Wi-Fi credentials and device IDs in cleartext, creating a risk for unauthorized access and control over connected YoLink devices.
Users are advised to treat the YoLink Smart Hub as untrusted, disconnect it from critical networks, and avoid using it for access control. Consider switching to vendors that provide regular security updates and independent security testing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 6, 2025CISA-ADP
Assessed Oct 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bishopfox.com/blog/advisories | [email protected] | AdvisoryBundle |
| https://bishopfox.com/blog/how-a-20-smart-device-gave-me-access-to-your-home | [email protected] | ExploitTechnical Analysis |
| https://shop.yosmart.com/pages/product-support | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YoSmart YoLink Smart Hub | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | New CVE Received | [email protected] |
Volerion