CVE-2025-65290
7.4Aqara · Camera Hub G3, Hub M2, Hub M3
Aqara Hub devices fail to validate server certificates during HTTPS firmware downloads, enabling man-in-the-middle attackers to intercept traffic and potentially inject malicious firmware updates.
Executive summary
A failure in certificate validation within multiple Aqara Hub devices allows unauthenticated attackers to perform man-in-the-middle attacks to compromise device firmware integrity.
Vulnerability
The vulnerability involves improper validation of HTTPS server certificates during the firmware update process. This flaw allows an unauthenticated, network-positioned attacker to intercept update traffic and serve unauthorized or malicious firmware files to the device.
Business impact
The ability to inject malicious firmware into IoT infrastructure poses a severe risk to organizational security. A successful exploit could lead to full device compromise, persistent unauthorized access to local network segments, and the exfiltration of sensitive video or environmental data. With a CVSS score of 7.4, this vulnerability represents a high-risk entry point for attackers to establish a foothold within the internal network.
Remediation
Immediate Action: Since a specific patch is currently unconfirmed, administrators should isolate affected Aqara Hubs within a restricted VLAN with no direct Internet access to prevent unauthorized firmware interception.
Proactive Monitoring: Monitor network traffic for unusual outbound requests from IoT devices to unknown or suspicious update servers.
Compensating Controls: Implement strict network segmentation and utilize an inspection-capable firewall to monitor and restrict the traffic flow of IoT devices, ensuring that only trusted update endpoints are reachable.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.
Analyst recommendation
Given the potential for complete device takeover via malicious firmware, organizations should prioritize the isolation of these devices from critical networks. Administrators must remain vigilant for vendor-issued firmware updates and apply them immediately upon release to remediate the certificate validation failure.