CVE-2025-66974: Prolink 13A Smart Plug vulnerability
Published Sep 15, 2026
·Updated
An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase.
Affected Software
2 affected components
Prolink 13A Smart Plug=DS-3202M-UKv3
mEzee=2.6.7
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
When can an attacker exploit this issue?
The crafted packet must be supplied during the smart plug's provisioning phase. The provided information does not identify any additional authentication or network-access prerequisites.
2
What outcomes can exploitation cause?
An attacker may cause a denial of service or cause a connection to an attacker-controlled device. The supplied information does not state whether either outcome persists after provisioning completes.