top of page
perceptive_background_267k.jpg

YoSmart YoLink Smart Hub

Published:

13 January 2026 at 12:00:00

Alert date:

13 January 2026 at 19:02:07

Source:

cisa.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

Multiple critical vulnerabilities discovered in YoSmart YoLink Smart Hub ecosystem allowing remote control of other users' smart home devices, session hijacking, and data interception. Four CVEs affect different components: CVE-2025-59449 enables cross-account attacks due to insufficient authorization controls, CVE-2025-59452 uses predictable endpoint URLs derived from MAC addresses, CVE-2025-59448 transmits sensitive data over unencrypted MQTT, and CVE-2025-59451 involves session tokens with excessively long lifetimes. The vulnerabilities could allow attackers to gain full control over any YoLink user's devices worldwide. YoSmart has released patches and automatic updates to address these issues.

Technical details

Mitigation steps:

Affected products:

YoSmart YoLink Smart Hub
YoLink Mobile Application
YoSmart server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page