CVE-2025-65292
7.3Aqara · Camera Hub G3, Hub M2, Hub M3
Aqara hub devices are vulnerable to command injection via malicious domain names, allowing local attackers with user privileges to execute arbitrary code with root-level access.
Executive summary
A critical command injection vulnerability in multiple Aqara Hub devices allows local attackers to gain root-level system control.
Vulnerability
The device suffers from a command injection flaw where processing malicious domain names permits an authenticated user to execute arbitrary commands at the root privilege level.
Business impact
Successful exploitation allows an attacker to achieve full system compromise, granting them root access to the affected hub. This could lead to total loss of device confidentiality, integrity, and availability, potentially allowing the attacker to pivot into the local network or disable security features. With a CVSS score of 7.3, this high-severity flaw represents a significant risk to residential and commercial security environments.
Remediation
Immediate Action: Disconnect affected hubs from public-facing network segments or untrusted network zones until a firmware patch is released by the vendor.
Proactive Monitoring: Review device access logs and network traffic for suspicious DNS requests or anomalous outbound connection attempts originating from the hub devices.
Compensating Controls: Implement strict network segmentation to isolate IoT devices from critical business or home network infrastructure, and restrict the hub's ability to resolve arbitrary external domains.
Exploitation status
Public Exploit Available: Yes, a technical write-up containing attack details is available via the researcher's report on GitHub.
Analyst recommendation
Given the potential for root-level command execution, users must prioritize isolating these devices from their primary network. Administrators should monitor the vendor support portal for firmware updates and apply them immediately upon release to remediate the underlying injection vulnerability.