Back to Database
Status published
Medium
CVE-2025-32901
In KDE Connect before 1.33.0 on Android, malicious device IDs...
Vulnerability Description
In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32901
Credits & Attribution
No credits recorded in the NVD database.
More from KDE
View All →CVE-2025-69412
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in...
Low
3.4
CVE-2025-66270
The KDE Connect protocol 8 before 2025-11-28 does not correlate...
Medium
4.7
CVE-2025-59820
In KDE Krita before 5.2.13, loading a manipulated TGA file...
Medium
6.7
CVE-2025-55174
In KDE Skanpage before 25.08.0, an attempt at file overwrite...
Low
3.2
CVE-2025-49091
KDE Konsole before 25.04.2 allows remote code execution in a...
High
8.2
Affected Vendor
Affected Software
KDEConnect
Vulnerable Versions:
0
Timeline
Official Publish:
December 5th, 2025
Last Modified:
December 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.