The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
History

Fri, 05 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent
Vendors & Products Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent

Fri, 05 Dec 2025 04:45:00 +0000

Type Values Removed Values Added
Description The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
Weaknesses CWE-331
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-05T00:00:00.000Z

Updated: 2025-12-05T14:40:16.425Z

Reserved: 2025-04-14T00:00:00.000Z

Link: CVE-2025-32898

cve-icon Vulnrichment

Updated: 2025-12-05T14:40:13.301Z

cve-icon NVD

Status : Received

Published: 2025-12-05T05:16:58.480

Modified: 2025-12-05T05:16:58.480

Link: CVE-2025-32898

cve-icon Redhat

No data.