The vulnerable implementations of KDE Connect were not checking that the device ID in the first packet and the device ID in ...