CVE-2025-66974
—Crafted Provisioning Packet Flaw in Prolink DS-3202M-UKv3 Smart Plug Enables DoS and Device Hijack
The Prolink 13A Smart Plug (model DS-3202M-UKv3, Wi-Fi variant) used with the mEzee mobile application version 2.6.7 improperly validates input during the device provisioning phase, classified as CWE-20 (Improper Input Validation). An attacker on the same network who supplies a specially crafted packet while the plug is being set up can crash the device, causing a denial of service, or redirect its connection to an attacker-controlled endpoint. The flaw is remotely exploitable over the network with no privileges or user interaction required, and carries a CVSS 3.1 base score of 7.5 (high), driven entirely by availability impact. Anyone setting up or re-provisioning an affected Prolink smart plug, particularly on shared or untrusted Wi-Fi networks, is potentially affected. The issue is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation is presumed to be theoretical at this time.
What to do: Contact Prolink support to check for a firmware or mEzee app update and apply it promptly if one exists. Perform initial provisioning and any factory resets on a trusted, isolated Wi-Fi network, since the attack window is during setup. After setup, verify the plug connects only to expected cloud endpoints, and consider replacing units still running the vulnerable configuration if no patch is offered.
| Prolink 13A Smart Plug DS-3202M-UKv3 (Wi-Fi) | — |
| Prolink mEzee companion application | 2.6.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.