CVE-2025-32900Use of Less Trusted Source in Connect Information-exchange Protocol

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 99.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5

Description

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Debiankde/kdeconnect< 25.04.0-1+1

🔴Vulnerability Details

3
OSV
CVE-2025-32900: In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a de2025-12-05
GHSA
GHSA-gxgp-vx99-mxcw: In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a de2025-12-05
CVEList
CVE-2025-32900: In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a de2025-12-05

📋Vendor Advisories

1
Debian
CVE-2025-32900: gnome-shell-extension-gsconnect - In the KDE Connect information-exchange protocol before 2025-04-18, a packet can...2025
CVE-2025-32900 — Use of Less Trusted Source | cvebase