
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-32898 is an insufficient entropy vulnerability in the KDE Connect verification-code protocol that allows adjacent network attackers to perform brute-force attacks against the pairing verification code. The protocol used only 8 characters in its verification code, providing insufficient randomness to resist brute-force attempts. Affected software includes KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before version 59. The vulnerability was disclosed on April 18, 2025, and has a CVSS v3.1 base score of 4.7 (Medium) (Red Hat Advisory, KDE Advisory).
The root cause is classified as CWE-331 (Insufficient Entropy): the KDE Connect device pairing protocol generated verification codes using only 8 characters, resulting in a small keyspace that can be exhausted through brute-force attacks. An attacker positioned on the same local network (adjacent network) as the target could intercept or repeatedly attempt pairing requests, systematically guessing the short verification code without requiring any privileges or user interaction. The attack complexity is rated High due to the requirement for network adjacency and timing constraints during the pairing window (KDE Advisory, Red Hat Advisory).
Successful exploitation could allow an unauthenticated attacker on the same network to bypass the device pairing verification and gain unauthorized access to a victim's KDE Connect session. This could result in limited confidentiality and integrity impacts — specifically, low-level exposure of data accessible through KDE Connect (such as notifications, clipboard content, or file transfers) and the ability to perform unauthorized actions on the paired device. Availability is not impacted, but the scope is marked as Changed, indicating that resources beyond the vulnerable component may be affected (Red Hat Advisory, KDE Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-32898. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be on the same local network and to act during the brief pairing window, which significantly limits practical exploitability (Red Hat Advisory, KDE Advisory).
nmap.Users should update to the patched versions: KDE Connect 1.33.0 or later on Android, KDE Connect 25.04 or later on desktop, KDE Connect 0.5 or later on iOS, Valent 1.0.0.alpha.47 or later, and GSConnect 59 or later. These versions implement a stronger verification-code protocol with sufficient entropy to resist brute-force attacks. As a workaround prior to patching, users should avoid initiating KDE Connect pairing on untrusted or public networks, and review their list of paired devices to remove any unrecognized entries (KDE Advisory, Red Hat Advisory).
A security disclosure blog post was published at cezarlungu.com detailing the KDE Connect security issue, indicating independent researcher interest in the vulnerability (Cezar Lungu Blog). The vulnerability was picked up by several vulnerability tracking services and security news aggregators shortly after disclosure. No major vendor statements beyond the KDE advisory or significant social media controversy have been identified.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
kdeconnect
devel
gnome-shell-extension-gsconnect
focal (esm-apps)
gnome-shell-extension-gsconnect
jammy
gnome-shell-extension-gsconnect
jammy (esm-apps)
gnome-shell-extension-gsconnect
noble
gnome-shell-extension-gsconnect
noble (esm-apps)
gnome-shell-extension-gsconnect
questing
gnome-shell-extension-gsconnect
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."