ZeroHour

CVE-2025-66974

Crafted Provisioning Packet Flaw in Prolink DS-3202M-UKv3 Smart Plug Enables DoS and Device Hijack

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

The Prolink 13A Smart Plug (model DS-3202M-UKv3, Wi-Fi variant) used with the mEzee mobile application version 2.6.7 improperly validates input during the device provisioning phase, classified as CWE-20 (Improper Input Validation). An attacker on the same network who supplies a specially crafted packet while the plug is being set up can crash the device, causing a denial of service, or redirect its connection to an attacker-controlled endpoint. The flaw is remotely exploitable over the network with no privileges or user interaction required, and carries a CVSS 3.1 base score of 7.5 (high), driven entirely by availability impact. Anyone setting up or re-provisioning an affected Prolink smart plug, particularly on shared or untrusted Wi-Fi networks, is potentially affected. The issue is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation is presumed to be theoretical at this time.

What to do: Contact Prolink support to check for a firmware or mEzee app update and apply it promptly if one exists. Perform initial provisioning and any factory resets on a trusted, isolated Wi-Fi network, since the attack window is during setup. After setup, verify the plug connects only to expected cloud endpoints, and consider replacing units still running the vulnerable configuration if no patch is offered.

Affected
Prolink 13A Smart Plug DS-3202M-UKv3 (Wi-Fi)
Prolink mEzee companion application2.6.7
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.