Unauthorized Data Upload in Aqara Hub Devices
CVE-2025-65297
7.5HIGH
What is CVE-2025-65297?
Aqara Hub devices, including the Camera Hub G3 (version 4.1.9_0027), Hub M2 (version 4.3.6_0027), and Hub M3 (version 4.3.6_0025), present a security issue by automatically collecting and transmitting unencrypted sensitive data. This unauthorized data upload occurs without any notification or consent from the user, posing significant privacy risks.
