CVE-2025-65295

8.1

Aqara · Camera Hub G3, Hub M2, Hub M3

Aqara hub devices contain multiple vulnerabilities in the firmware update process, allowing unauthenticated attackers to install malicious firmware due to improper signature verification.

Executive summary

Critical vulnerabilities in Aqara Hub firmware allow unauthenticated attackers to execute arbitrary code via malicious firmware installation, necessitating immediate attention.

Vulnerability

The device firmware update process fails to validate digital signatures and utilizes outdated cryptographic methods, which allows an unauthenticated attacker to forge signatures and install malicious firmware. Furthermore, the devices exhibit information exposure due to improperly initialized memory.

Business impact

The ability to install malicious firmware grants an attacker complete control over the affected smart home hubs, leading to unauthorized access to sensitive video streams, home network compromise, and potential data exfiltration. With a CVSS score of 8.1, this high-severity flaw poses a significant risk to user privacy and physical security, as compromised hubs may be used as persistent entry points into the local network.

Remediation

Immediate Action: Contact Aqara support or monitor the official vendor security portal for the release of patched firmware versions for the identified models.

Proactive Monitoring: Review network traffic logs for unusual outbound connections from hub devices, particularly those communicating with unknown external servers during update intervals.

Compensating Controls: Isolate smart home hubs on a restricted VLAN to minimize the potential lateral movement if a device is compromised, and ensure external access to the devices is disabled where possible.

Exploitation status

Public Exploit Available: Yes, a technical write-up containing the attack detail exists via the research report referenced in the CVE record.

Analyst recommendation

Given the high severity of this vulnerability and the potential for full device compromise, users must treat these devices as high-risk assets until firmware updates are applied. Organizations and home users should prioritize network segmentation for these hubs immediately to limit the blast radius of a potential exploitation event.

More Aqara CVEs

Sources