CVE-2025-65293Medium· 6.6▾ SunlitCommand injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
camera_hub_g3_firmware = 4.1.9_0027Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-65294Critical· 9.8Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
CVE-2025-65292High· 7.3Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
CVE-2025-14108High· 8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-14106High· 8.8A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050