PatchSiren cyber security CVE debrief
CVE-2025-59451 YoSmart CVE debrief
CVE-2025-59451 is a low-severity YoSmart YoLink issue disclosed publicly by CISA on 2026-01-13. The advisory says the YoSmart YoLink application through 2025-10-02 had session tokens with unexpectedly long lifetimes, which can extend the usable window for an active session. CISA also states the issue was resolved on the server backend and that no user actions are required.
- Vendor
- YoSmart
- Product
- YoLink Smart Hub
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-01-13
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-01-13
Who should care
YoSmart YoLink Smart Hub users, administrators, and teams that rely on the platform in managed or operational environments should be aware of the advisory and confirm account/session hygiene.
Technical summary
The source advisory describes a session management weakness affecting YoSmart YoLink components, including YoLink Smart Hub and the YoLink mobile application, where session tokens persisted longer than intended through 2025-10-02. The supplied CVSS 3.1 vector is AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N, which aligns with a network-reachable issue requiring some privileges and resulting in limited integrity impact rather than confidentiality or availability impact. CISA’s remediation note says YoSmart resolved the vulnerabilities on the server backend, so the fix is not dependent on end-user patching.
Defensive priority
Low. Track the advisory for confirmation that sessions behave normally, but no user-side remediation is required per YoSmart/CISA.
Recommended defensive actions
- Treat the issue as already remediated on the vendor backend; no direct user patch action is required.
- If you administer shared or sensitive accounts, review session and account-access practices to ensure old sessions are not unnecessarily trusted.
- Follow standard CISA ICS recommended practices for defensive account hygiene and access control.
- Monitor the official YoSmart security advisory for any follow-up guidance or clarification.
Evidence notes
The facts in this brief come from the CISA CSAF advisory ICSA-26-013-03 and the linked CVE record. The advisory description states that the YoSmart YoLink application through 2025-10-02 had session tokens with unexpectedly long lifetimes, and the remediation section states the vulnerabilities were resolved on the server backend with no user action required. The CVE is publicly dated 2026-01-13; that date is used here for disclosure context.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-59451 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-59451
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-59451 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-59451
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-013-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-013-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.