CVE-2025-65296

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*

History

17 Dec 2025, 19:46

Type Values Removed Values Added
First Time Aqara hub M3
Aqara hub M3 Firmware
Aqara camera Hub G3 Firmware
Aqara
Aqara hub M2
Aqara camera Hub G3
Aqara hub M2 Firmware
References () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/JSON-NULL-Dereference.md - () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/JSON-NULL-Dereference.md - Exploit, Third Party Advisory
CPE cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*

11 Dec 2025, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-476

10 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 22:16

Updated : 2025-12-17 19:46


NVD link : CVE-2025-65296

Mitre link : CVE-2025-65296

CVE.ORG link : CVE-2025-65296


JSON object : View

Products Affected

aqara

  • hub_m3
  • camera_hub_g3_firmware
  • hub_m2
  • hub_m3_firmware
  • hub_m2_firmware
  • camera_hub_g3
CWE
CWE-476

NULL Pointer Dereference