PT-2026-48914 · Aqara · Aqara Cloud
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Aqara Cloud (affected versions not specified)
Description
The OAuth Authorization Endpoint "open-cn.aqara.com/oauth/authorize" is subject to a redirect bypass caused by improper validation of unsafe equivalence in input. This flaw allows for domain matching bypass, which can be leveraged to facilitate phishing attacks and session theft.
Recommendations
Disable OAuth integration until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aqara Cloud