CVE-2025-59449 - CVE House
Back to Database
Status published Medium CVE-2025-59449

The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce...

Vulnerability Description

The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59449

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

YoLink MQTT broker
Vulnerable Versions:
0

Timeline

Official Publish: October 6th, 2025
Last Modified: November 26th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Weaknesses (CWE)