YoLink YS1603-UC hub vulnerabilities

Someone just pointed me to this article, which documents multiple vulnerabilities around the YS1603-UC hub. There doesn’t seem to be anywhere else to discuss this (the YoLink Discord has been dead for quite some time) so I thought I’d post it here since there’s quite a few HA YoLink users.

The problem with “just patch it then” is that there are two and possibly three completely different things all branded as the YS1603-UC. The article talks about an ESP32-WROOM-32 and FW 0382 but that only came out some time in 2017 which is far more recent than my hub, which has FW 0320. Someone with a much newer hub who contacted YoLink about this issue was told their hub had old hardware and couldn’t get updated FW, which means there may be a third hardware version as well that can still get newer FW.

So if you have a YoLink YS1603-UC hub older than late 2025 you’re probably vulnerable, unless it’s much older than 2025 in which case it may have the same or different vulnerabilities due to different hardware/FW.

Yolink addressed it here

Yes, that’s exactly the press release I linked to in my post. That doesn’t actually fix the problem for the majority of YoLink users.

I wouldn’t say a majority of users. Affected devices were automatically updated via pushed OTA updates as the bulletin states.

No, they weren’t. Because there are two and possibly three different types of hubs out there all with the same model number, it’s unclear which versions were actually updated. Of the three people I know with YoLink gear, a total of zero have been updated. I counted them twice.

To find out whether you’re affected, check your FW version. If it’s less than 38someting this vuln hasn’t been patched, and possibly never will be.

Here’s an easier way to find out whether you’re affected: The FCC database lists two of the devices, there’s this one (older hardware) and this one (newer hardware). They’re completely different internally even though the model number remained the same, the only way to tell what you’ve got is to look at the FCC ID, which is 2ATM71603 for the older hardware and 2ATM71603M for newer. The FCC info from the newer one is from 2023 and presumably they didn’t get it to market and clear their channels of existing stock instantly so let’s say if you got a hub before maybe late 2023 or early 2024 you’re vulnerable and there’s no fix available.

The older hub FCC info is from 2019 and I’m pretty sure I got mine before then so there may be a third model out there too. Both the 2019 and 2023-ID’d models have WROOM-32’s in them so I’m not sure why they can provide updates for one and not the other.

You mentioned Someone with a much newer hub who contacted YoLink about this issue was told their hub had old hardware and couldn’t get updated FW, but have you personally reached out to Yolink with your issue?

I found their customer service to be very responsive to device issues. They have replaced two of my devices that failed at no cost. I experienced a water smart valve that leaked and their local hub that bricked with a firmware update.

That would mean the FCC and the ETSI both missed that model.

I’ve always found them to be really good too so not complaining there, just wondering if they’ll replace something that’s waaaay out of warranty. For now I’m still trying to figure out what’s what, whether I can update mine or do I need to ask for a newer version, or just go to the local hub if they’ve finally got the bugs worked out on that one.

In terms of a possible third version of the hub, I’ve seen photos of one with text above the LEDs instead of symbols but I don’t know if that’s a really, really old model, a yet-to-be-released one, or a mockup of a nonexistent one.

I’d still ask, couldn’t hurt..

My water valve was out of warranty, and they only required that I return the damaged unit. For the local hub, they sent me a brand-new replacement without asking for the bricked one back.

I pinged YoLink about it and the status is:

The security vulnerability referenced in the advisory applies only to hubs in the 038X firmware series. Hubs running firmware version 0320 are not affected by this issue.

This vulnerability is specific to newer hub hardware. Based on the firmware version you reported, your hub is a 2021 model, which is not impacted by this security vulnerability. Therefore, there is no need to update your hub to firmware version 0383, and version 0320 is the correct and latest firmware available for your device.

So by the looks of it they did a fairly significant redo with the newer hub, possibly LoRaWAN security back to the server for the older model but terminating at the hub and then plaintext MQTT the rest of the way for the newer one. At some point I may set up mirroring on the port the Yolink is on so I can capture the traffic and see what it’s actually doing.