PT-2025-50536 · Aqara · Aqara Camera Hub G3+2
Published
2025-12-10
·
Updated
2025-12-14
·
CVE-2025-65291
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Aqara Hub M2 version 4.3.6 0027
Aqara Hub M3 version 4.3.6 0025
Aqara Camera Hub G3 version 4.1.9 0027
Description
Aqara Hub devices do not properly validate server certificates during TLS connections used for discovery services and CoAP gateway communications. This flaw allows for man-in-the-middle attacks, potentially compromising device control and monitoring. CoAP (Constrained Application Protocol) is a specialized web transfer protocol for constrained devices and networks. TLS (Transport Layer Security) is a cryptographic protocol that provides secure communication over a network.
Recommendations
Update Aqara Hub M2 to a version after 4.3.6 0027.
Update Aqara Hub M3 to a version after 4.3.6 0025.
Update Aqara Camera Hub G3 to a version after 4.1.9 0027.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aqara Camera Hub G3
Aqara Hub M2
Aqara Hub M3