VYPR

YoLink

by YoSmart

CVEs (2)

  • CVE-2025-59452MedOct 6, 2025
    risk 0.38cvss 5.8epss 0.00

    The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

  • CVE-2025-59451LowOct 6, 2025
    risk 0.23cvss 3.5epss 0.00

    The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.