PT-2026-48909 · Aqara · Board Service

Sammy Azdoufal

+1

·

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-50085

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-50085

Affected Products

Board Service