Certificate Validation Bypass in Aqara Hub Devices
CVE-2025-65290

7.4HIGH

Key Information:

Vendor

Aqara

Status
Vendor
CVE Published:
10 December 2025

What is CVE-2025-65290?

Aqara Hub devices including Camera Hub G3, Hub M2, and Hub M3 exhibit a critical flaw where they do not properly validate server certificates during HTTPS firmware downloads. This lack of validation allows a potential attacker to execute a man-in-the-middle attack, intercept the traffic involved in firmware updates, and serve modified firmware files to users. Such exposure could lead to unauthorized access or control over the affected devices, posing a significant threat to user security and privacy.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.