CVE-2025-65290
- EPSS 0.03%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:55:56
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potenti...
CVE-2025-65291
- EPSS 0.03%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 15.01.2026 17:04:50
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device co...
CVE-2025-65292
- EPSS 0.06%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:55:09
Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.
CVE-2025-65293
- EPSS 0.08%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:52:09
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
CVE-2025-65294
- EPSS 1.01%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:51:48
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
CVE-2025-65295
- EPSS 0.03%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:49:47
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate f...
CVE-2025-65296
- EPSS 0.04%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 19:46:26
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
CVE-2025-65297
- EPSS 0.02%
- Veröffentlicht 10.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 17:15:20
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.