Security researchers at Bishop Fox uncovered multiple zero-day vulnerabilities in the YoLink Smart Hub (v0382), a widely used and inexpensive IoT gateway device that manages smart locks, sensors, plugs, and other home automation products. The vulnerabilities, which were disclosed publicly and assigned four separate CVEs, include a critical authorization bypass that allows remote attackers to control devices belonging to other users. This flaw, tracked as CVE-2025-59449 and CVE-2025-59452, stems from insufficient authorization controls, enabling hackers to exploit predictable device IDs and gain unauthorized access to smart home systems. Researchers demonstrated the ability to remotely operate a smart lock in a different user’s home, highlighting the real-world impact of the vulnerabilities. Another critical issue, CVE-2025-59448, involves the transmission of sensitive data, such as Wi-Fi credentials and device IDs, in cleartext over the network, making it possible for attackers to intercept and misuse this information. The YoLink Smart Hub uses the ESP32 System-on-Chip and communicates with mobile apps via the MQTT protocol, distributing commands to devices using LoRa or LoRaWAN radio technology. The research found that the hub’s session management is flawed, with long-lived tokens that allow ongoing unauthorized access once compromised. All users of the YoLink Smart Hub v0382 are at risk, as the device serves as the central point of control for all connected YoLink products. The vulnerabilities were discovered through hands-on hardware analysis and reverse engineering of the device’s firmware and communication protocols. The researchers recommend treating the YoLink hub as untrusted, disconnecting or segmenting it from critical networks, and avoiding its use for access control purposes. They also advise consumers to consider switching to vendors that provide regular security updates and independent security testing. The findings underscore the broader risks associated with deploying low-cost, poorly secured IoT devices in home environments. The disclosure of these vulnerabilities serves as a warning to both consumers and manufacturers about the importance of robust security practices in the rapidly growing smart home market. The research highlights the ease with which attackers can exploit insecure IoT devices, often available for as little as $20, to gain access to private homes. The incident demonstrates the need for improved security standards and regular patching in the IoT ecosystem. The YoLink vulnerabilities exemplify how a single compromised device can jeopardize the security of an entire smart home network. The public disclosure aims to prompt both users and manufacturers to take immediate action to mitigate these risks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Bishop Fox published research describing multiple security flaws in the low-cost YoLink Hub smart-home gateway, including issues that could allow unauthorized access to connected home devices and security functions. A contemporaneous report highlighted the same disclosure and its potential impact on home security users.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.