CVE-2025-65290
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-17
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aqara | hub_m2_firmware | 4.3.6_0027 |
| aqara | hub_m2 | * |
| aqara | hub_m3_firmware | 4.3.6_0025 |
| aqara | hub_m3 | * |
| aqara | camera_hub_g3_firmware | 4.1.9_0027 |
| aqara | camera_hub_g3 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects Aqara Hub devices, including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025. These devices fail to validate server certificates during HTTPS firmware downloads, which allows man-in-the-middle attackers to intercept the firmware update traffic and potentially serve modified firmware files.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to intercept and modify firmware updates sent to Aqara Hub devices. This could lead to the installation of malicious firmware, potentially compromising the device's security, functionality, and the privacy of the user.