VulnSea

aqara has 8 CVEs on record. The busiest recent month was December 2025 with 8. The median CVSS is 7.4 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: hub_m2_firmware (7), camera_hub_g3_firmware (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
—
Last 90 days
0 prev 0

Products

  • hub_m2_firmware 7
  • camera_hub_g3_firmware 1
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

aqara vulnerabilities

CVEs affecting aqara, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2025-65297High· 7.5
9mo ago

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.

▾ Twilightaqara · hub_m2_firmwareEPSS 0.19%via NVD
CVE-2025-65296Medium· 6.5
9mo ago

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

▾ Sunlitaqara · hub_m2_firmwareEPSS 0.28%via NVD
CVE-2025-65295High· 8.1
9mo ago

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails …

▾ Twilightaqara · hub_m2_firmwareEPSS 0.23%via NVD
CVE-2025-65294Critical· 9.8
9mo ago

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

▾ Midnightaqara · hub_m2_firmwareEPSS 0.98%via NVD
CVE-2025-65293Medium· 6.6
9mo ago

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

▾ Sunlitaqara · camera_hub_g3_firmwareEPSS 1.1%via NVD
CVE-2025-65292High· 7.3
9mo ago

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

▾ Twilightaqara · hub_m2_firmwareEPSS 0.80%via NVD
CVE-2025-65291High· 7.4
9mo ago

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks…

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks…

▾ Twilightaqara · hub_m2_firmwareEPSS 0.18%via NVD
CVE-2025-65290High· 7.4
9mo ago

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffi…

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffi…

▾ Twilightaqara · hub_m2_firmwareEPSS 0.18%via NVD
aqara vulnerabilities (CVEs) · VulnSea