CVE-2025-32899
Description
A flaw was found in KDE Connect. This vulnerability allows two paired devices to unpair via an invalid discovery packet sent over broadcast User Datagram Protocol (UDP).
Statement
This vulnerability is rated Moderate for Red Hat as it allows an unauthenticated attacker on the same local network segment to unpair KDE Connect devices. This flaw primarily impacts the availability of the KDE Connect service by disrupting established device pairings.
Mitigation
To mitigate this issue, restrict network access to systems running KDE Connect. Configure firewall rules to limit UDP traffic on the KDE Connect discovery port (default 1716) to only allow communication from trusted hosts or subnets. This may impact the ability of KDE Connect to discover and pair with new devices if not configured correctly.
Understanding the Weakness (CWE)
Other
Technical Impact: Unexpected State
One or more of the components/sub-systems could assume that the state is different than it actually is.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.