SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-66974

HIGH · CVSS 7.5 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Prolink 13A Smart Plug Model DS-3202M-UKv3, running mEzee version 2.6.7, is vulnerable to a Denial of Service (DoS) attack, which can be triggered by sending a specially crafted packet during the device's provisioning phase. This vulnerability allows attackers to disrupt service or redirect connections to malicious devices. Organizations using this smart plug should prioritize patching or mitigating this issue to safeguard their network and connected devices.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-66974
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase.