CVE-2025-65290

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*

History

17 Dec 2025, 19:55

Type Values Removed Values Added
References () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Certificate-Validation-Bypass.md - () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Certificate-Validation-Bypass.md - Exploit, Third Party Advisory
First Time Aqara hub M3
Aqara hub M3 Firmware
Aqara camera Hub G3 Firmware
Aqara
Aqara hub M2
Aqara camera Hub G3
Aqara hub M2 Firmware
CPE cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*

11 Dec 2025, 17:15

Type Values Removed Values Added
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

10 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 22:16

Updated : 2025-12-17 19:55


NVD link : CVE-2025-65290

Mitre link : CVE-2025-65290

CVE.ORG link : CVE-2025-65290


JSON object : View

Products Affected

aqara

  • hub_m3
  • camera_hub_g3_firmware
  • hub_m2
  • hub_m3_firmware
  • hub_m2_firmware
  • camera_hub_g3
CWE
CWE-295

Improper Certificate Validation