7.5

CVE-2025-65297

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aqara ≫ Hub M2 Firmware Version 4.3.6_0027
   Aqara ≫ Hub M2 Version -
Aqara ≫ Hub M3 Firmware Version 4.3.6_0025
   Aqara ≫ Hub M3 Version -
Aqara ≫ Camera Hub G3 Firmware Version 4.1.9_0027
   Aqara ≫ Camera Hub G3 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-5 J2EE Misconfiguration: Data Transmission Without Encryption

Information sent over a network can be compromised while in transit. An attacker may be able to read or modify the contents if the data are sent in plaintext or are weakly encrypted.

https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/Unauthorized-Data-Upload.md
Third Party Advisory