CVE-2025-65291
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-10

Last updated on: 2025-12-12

Assigner: MITRE

Description
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-10
Last Modified
2025-12-12
Generated
2026-05-07
AI Q&A
2025-12-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
aqara camera_hub_g3 4.1.9_0027
aqara hub_m2 4.3.6_0027
aqara hub_m3 4.3.6_0025
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects Aqara Hub devices (Hub M2, Hub M3, Camera Hub G3) where they fail to properly validate server certificates during TLS connections used for discovery services and CoAP gateway communications. This flaw allows attackers to perform man-in-the-middle attacks, intercepting or altering device control and monitoring communications.


How can this vulnerability impact me? :

The vulnerability can allow attackers to intercept, manipulate, or eavesdrop on communications between the Aqara Hub devices and their servers. This could lead to unauthorized control of the devices, exposure of sensitive monitoring data, and potential compromise of the smart home environment.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart