---
id: CVE-2025-65295
title: >-
  Multiple vulnerabilities in Aqara Hub firmware update process in the Camera
  Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow
  attackers to install malicious firmware without proper verification
summary: >-
  Multiple vulnerabilities in Aqara Hub firmware update process in the Camera
  Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow
  attackers to install malicious firmware without proper verification. The
  device fails …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-326
  - CWE-347
  - CWE-457
vendor: aqara
product: hub_m2_firmware
affected:
  - hub_m2_firmware = 4.3.6_0027
  - hub_m3_firmware = 4.3.6_0025
  - camera_hub_g3_firmware = 4.1.9_0027
published: '2025-12-10'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65295'
references:
  - url: >-
      https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Firmware-Insecurity.md
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00233
epssPercentile: 0.12709
ingestedAt: '2026-09-25T23:21:16.940Z'
---

## Overview

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic methods that can be exploited to forge valid signatures, and exposes information through improperly initialized memory.

## Affected

- `hub_m2_firmware = 4.3.6_0027`
- `hub_m3_firmware = 4.3.6_0025`
- `camera_hub_g3_firmware = 4.1.9_0027`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
