CVE-2025-65291
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-12
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aqara | camera_hub_g3 | 4.1.9_0027 |
| aqara | hub_m2 | 4.3.6_0027 |
| aqara | hub_m3 | 4.3.6_0025 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects Aqara Hub devices (Hub M2, Hub M3, Camera Hub G3) where they fail to properly validate server certificates during TLS connections used for discovery services and CoAP gateway communications. This flaw allows attackers to perform man-in-the-middle attacks, intercepting or altering device control and monitoring communications.
How can this vulnerability impact me? :
The vulnerability can allow attackers to intercept, manipulate, or eavesdrop on communications between the Aqara Hub devices and their servers. This could lead to unauthorized control of the devices, exposure of sensitive monitoring data, and potential compromise of the smart home environment.