CVE-2025-66270

EUVD-2025-201386
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
mitreCNA
4.7 MEDIUM
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Debian logo
Debian Releases
Debian Product
Codename
gnome-shell-extension-gsconnect
bookworm
54-2
not-affected
bullseye
not-affected
forky
71-1
fixed
sid
71-1
fixed
trixie
62-1+deb13u1
fixed
trixie (security)
62-1+deb13u1
fixed
kdeconnect
bookworm
22.12.3-1
not-affected
bullseye
20.12.3-2
not-affected
forky
25.11.80+git20251121.7090b106-1
fixed
sid
25.11.80+git20251121.7090b106-1
fixed
trixie
25.04.2-1+deb13u1
fixed
trixie (security)
25.04.2-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kdeconnect
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
Fixed 25.08.1-0ubuntu2.1
released
xenial
not-affected
gnome-shell-extension-gsconnect
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
ignored
questing
needed