PT-2025-50544 · Aqara · Aqara Hub

Junming Chen

+4

·

Published

2025-12-10

·

Updated

2025-12-14

·

CVE-2025-65295

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aqara Hub versions 4.1.9 0027, 4.3.6 0027, and 4.3.6 0025
Description The Aqara Hub firmware update process has flaws that could allow attackers to install malicious firmware without proper verification. The device does not validate firmware signatures during updates and utilizes outdated cryptographic methods susceptible to signature forgery. Additionally, the device reveals information due to improperly initialized memory.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Improper Verification of Cryptographic Signature

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-65295

Affected Products

Aqara Hub