CVE-2025-59452: Yosmart Yolink API

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

Affected products

  • Yosmart Yolink API: up to and including 2025-10-02

Published 2025-10-06. Last modified 2026-10-09.