PT-2026-48906 · Aqara · Cloud Developer Portal

Sammy Azdoufal

+1

·

Publicado

2026-06-12

·

Atualizado

2026-06-12

·

CVE-2026-50082

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVE-2026-50085 - Aqara Board IoT insecure debug API
CVE ID :CVE-2026-50085 Published : June 12, 2026, 4:16 p.m. | 1 hour, 18 minutes ago Description :The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-50082

Produtos afetados

Cloud Developer Portal