MQTT credential disclosure via predictable profile endpoint
Published Oct 6, 2025 · Updated Oct 6, 2025
Predictable identifiers in the YoSmart API through 2025-10-02 allow remote attackers to retrieve YoLink Hub MQTT credentials. The Hub profile endpoint combines a guessable MAC address with an MD5 digest of the device ID and a static non-secret value, then returns broker credentials. No authentication is required; possession or enumeration of a Hub MAC address exposes MQTT credentials that permit message interception, including Wi-Fi credentials, but not device-control publication.
Summary
What happened
Predictable identifiers in the YoSmart API through 2025-10-02 allow remote attackers to retrieve YoLink Hub MQTT credentials. The Hub profile endpoint combines a guessable MAC address with an MD5 digest of the device ID and a static non-secret value, then returns broker credentials. No authentication is required; possession or enumeration of a Hub MAC address exposes MQTT credentials that permit message interception, including Wi-Fi credentials, but not device-control publication.
The record
- CVE
- CVE-2025-59452
- Published
- Oct 6, 2025
- Updated
- Oct 6, 2025
- Vendor
- YoSmart
- Product
- YoSmart API
- Classifications
- CWE-340, T1552
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Oct 6, 2025CVE publishedPublication date reported by the CVE source.
- Oct 6, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=2025-10-02
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Bishop Fox predictable profile endpoint demonstrationproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo