CVE-2025-65296

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*

History

17 Dec 2025, 19:46

Type Values Removed Values Added
First Time Aqara hub M3
Aqara hub M2
Aqara camera Hub G3 Firmware
Aqara hub M2 Firmware
Aqara hub M3 Firmware
Aqara
Aqara camera Hub G3
CPE cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*
cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*
cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*
cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*
References () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/JSON-NULL-Dereference.md - () https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/JSON-NULL-Dereference.md - Exploit, Third Party Advisory

11 Dec 2025, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-476

10 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 22:16

Updated : 2025-12-17 19:46


NVD link : CVE-2025-65296

Mitre link : CVE-2025-65296

CVE.ORG link : CVE-2025-65296


JSON object : View

Products Affected

aqara

  • hub_m3
  • camera_hub_g3
  • hub_m2
  • hub_m3_firmware
  • camera_hub_g3_firmware
  • hub_m2_firmware
CWE
CWE-476

NULL Pointer Dereference