📦 Hub M3 Firmware

by Aqara

🔍 What is Hub M3 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65294

CRITICAL CVSS 9.8 Dec 10, 2025

Aqara Hub devices contain an undocumented remote access mechanism that allows attackers to execute arbitrary commands without authentication. This vulnerability affects Aqara Camera Hub G3, Hub M2, an...

CVE-2025-65295

HIGH CVSS 8.1 Dec 10, 2025

This CVE describes vulnerabilities in Aqara Hub firmware update processes that allow attackers to install malicious firmware without proper signature validation. Attackers can exploit outdated cryptog...

CVE-2025-65297

HIGH CVSS 7.5 Dec 10, 2025

Aqara Hub devices automatically collect and upload unencrypted sensitive information without user consent or manufacturer disclosure. This vulnerability allows unauthorized data exfiltration affecting...

CVE-2025-65290

HIGH CVSS 7.4 Dec 10, 2025

Aqara Hub devices fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept update traffic and serve malicious firmware. This affects Came...

CVE-2025-65291

HIGH CVSS 7.4 Dec 10, 2025

Aqara Hub devices fail to validate TLS server certificates during discovery and CoAP communications, allowing man-in-the-middle attackers to intercept and manipulate device control and monitoring traf...

CVE-2025-65292

HIGH CVSS 7.3 Dec 10, 2025

A command injection vulnerability in Aqara Hub devices allows attackers to execute arbitrary commands with root privileges by exploiting malicious domain names. This affects Aqara Camera Hub G3, Hub M...

CVE-2025-65296

MEDIUM CVSS 6.5 Dec 10, 2025

A NULL-pointer dereference vulnerability in Aqara smart home hubs allows attackers to cause denial-of-service by sending malformed JSON inputs. This affects Aqara Hub M2, Hub M3, and Camera Hub G3 dev...