{"id":"CVE-2025-32898","title":"The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks","summary":"The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 …","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-331"],"published":"2025-12-05","updated":"2026-09-25","sourceUpdated":"2026-09-25T23:10:00.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-32898","references":[{"url":"https://kde.org/info/security/advisory-20250418-3.txt","label":"cve@mitre.org"},{"url":"https://kdeconnect.kde.org","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00148,"epssPercentile":0.0334,"ingestedAt":"2026-09-25T23:21:16.886Z","slug":"CVE-2025-32898","body":"## Overview\n\nThe KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}