Insufficient verification of data authenticity in KDE.org products - CVE-2025-32900

 

Insufficient verification of data authenticity in KDE.org products - CVE-2025-32900

Published: April 18, 2025


Vulnerability identifier: #VU107600
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-32900
CWE-ID: CWE-345
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to impersonate other devices on the network.

The vulnerability exists due to the way KDE Connect handles broadcasts and discovers devices inside the network. A remote attacker on the local network can send broadcast UDP packets that contain display name of another system and perform spoofing attack.


Affected software

KDE Connect
KDE Connect Android
KDE Connect iOS

How to mitigate CVE-2025-32900

Install updates from vendor's website.

KDE Connect - update to 25.04.0
KDE Connect Android - update to 1.33.0
KDE Connect iOS - update to 0.5.0

External References

Related Security Bulletins