CVE-2025-65297

7.5

Aqara · Camera Hub G3, Hub M2, Hub M3

Aqara Hub devices transmit sensitive user information in an unencrypted format to external servers without user disclosure or explicit consent.

Executive summary

Several Aqara Hub models are vulnerable to unauthorized data exfiltration due to the transmission of sensitive information in cleartext, posing a significant privacy risk to users.

Vulnerability

This vulnerability involves the automatic collection and transmission of unencrypted sensitive data by the device firmware. The issue is triggered without any requirement for user interaction or authentication, effectively exposing data to potential interception over the network.

Business impact

The exposure of sensitive information through unencrypted channels can lead to the unauthorized collection of private user data, violating privacy regulations and damaging brand trust. With a CVSS score of 7.5, this high severity vulnerability highlights the risk of widespread data leakage from smart home infrastructure. Organizations and residential users face potential surveillance risks if this traffic is intercepted by malicious actors on the local or wide area network.

Remediation

Immediate Action: Since a specific patch is not currently confirmed, users should restrict these devices to isolated network segments or VLANs to prevent unauthorized outbound traffic.

Proactive Monitoring: Network administrators should monitor traffic originating from the affected hubs for unusual outbound connections to unknown or non-essential external IP addresses.

Compensating Controls: Implement egress filtering on the network firewall to block outbound connections from the affected devices that are not strictly required for their intended functionality.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

Given the sensitive nature of the data being transmitted and the lack of user consent, users should prioritize isolating these devices from critical networks. Organizations utilizing these products should verify the necessity of their deployment until the manufacturer provides a firmware update that enforces encryption for all outgoing data streams.

More Aqara CVEs

Sources