NULL-Pointer Dereference Vulnerability in Aqara Hub Products
CVE-2025-65296

6.5MEDIUM

Key Information:

Vendor

Aqara

Status
Vendor
CVE Published:
10 December 2025

What is CVE-2025-65296?

Aqara Hub devices, specifically the M2, M3, and Camera Hub G3, are exposed to a NULL-pointer dereference vulnerability stemming from improper handling of JSON inputs. Attackers can exploit this flaw by sending malformed JSON data, leading to potential denial-of-service scenarios. It is crucial for users of affected Aqara products to remain vigilant and apply any available patches to protect against such attacks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.