The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-05 05:16
Updated : 2025-12-08 18:27
NVD link : CVE-2025-32898
Mitre link : CVE-2025-32898
CVE.ORG link : CVE-2025-32898
JSON object : View
Products Affected
No product.
CWE
CWE-331
Insufficient Entropy
