Executive brief
Prolink's 13A Smart Plug allows attackers to hijack device provisioning by replaying authentication tokens from legitimate users. An attacker can intercept Wi-Fi packets during setup, replay them with their own credentials, and cause the device to connect to the attacker's account instead of the legitimate owner's, resulting in unauthorized device control and potential network compromise.
Technical details
The vulnerability is a broken authentication / token validation bypass in the device provisioning phase. The smart plug and mEzee application lack verification that an authentication token presented during provisioning belongs to the legitimate device owner; instead, the device accepts replayed Wi-Fi packets containing attacker-supplied tokens. An attacker positioned on the network during provisioning can capture legitimate setup packets, replace the authentication token with their own, and replay the modified packet, causing the plug to bind to the attacker's cloud account. No user interaction or authentication is required; only network adjacency during the brief provisioning window. Successful exploitation results in the attacker gaining full control of the IoT device and potential access to home automation or network functions. Patch availability is not confirmed; tested versions include 2.7.2.
Affected products
- Prolink 13A Smart Plug DS-3202M DS-3202M-UKv3; mEzee application 2.6.7 to 2.7.2
Timeline
- 2025-09-15: disclosed
- 2025: other: CVE-2025-66974 assigned