In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Google android Kde Kde gsconnect Kde kde Kde kdeconnect Kde valent |
|
| Vendors & Products |
Apple
Apple ios Google android Kde Kde gsconnect Kde kde Kde kdeconnect Kde valent |
Fri, 05 Dec 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59. | |
| Weaknesses | CWE-348 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-05T14:14:16.977Z
Reserved: 2025-04-14T00:00:00.000Z
Link: CVE-2025-32900
Updated: 2025-12-05T14:14:13.508Z
Status : Received
Published: 2025-12-05T06:16:08.900
Modified: 2025-12-05T06:16:08.900
Link: CVE-2025-32900
No data.