Aqara

Hub M2 Firmware

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 19:55:56

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potenti...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 15.01.2026 17:04:50

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device co...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 19:55:09

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 19:51:48

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 19:49:47

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate f...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 19:46:26

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

  • EPSS 0.02%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 19.12.2025 17:15:20

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.