CVE-2025-59452: Yosmart Yolink API
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.
Affected products
- Yosmart Yolink API: up to and including 2025-10-02
Published 2025-10-06. Last modified 2026-10-09.