Security Advisory
CVE-2025-59452
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a devices MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.