CVE-2025-65290

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*

History

17 Dec 2025, 19:55

Type Values Removed Values Added
CPE cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*
References () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Certificate-Validation-Bypass.md - () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Certificate-Validation-Bypass.md - Exploit, Third Party Advisory
First Time Aqara hub M3
Aqara hub M2
Aqara camera Hub G3 Firmware
Aqara hub M2 Firmware
Aqara hub M3 Firmware
Aqara
Aqara camera Hub G3

11 Dec 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
CWE CWE-295

10 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 22:16

Updated : 2025-12-17 19:55


NVD link : CVE-2025-65290

Mitre link : CVE-2025-65290

CVE.ORG link : CVE-2025-65290


JSON object : View

Products Affected

aqara

  • hub_m3
  • camera_hub_g3
  • hub_m2
  • hub_m3_firmware
  • camera_hub_g3_firmware
  • hub_m2_firmware
CWE
CWE-295

Improper Certificate Validation