PT-2025-50544 · Aqara · Aqara Hub

·

CVE-2025-65295

·

Published

2025-12-10

·

Updated

2025-12-14

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aqara Hub versions 4.1.9 0027, 4.3.6 0027, and 4.3.6 0025
Description The Aqara Hub firmware update process has flaws that could allow attackers to install malicious firmware without proper verification. The device does not validate firmware signatures during updates and utilizes outdated cryptographic methods susceptible to signature forgery. Additionally, the device reveals information due to improperly initialized memory.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Improper Verification of Cryptographic Signature

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65295

Affected Products

Aqara Hub