{"resultsPerPage":18,"startIndex":0,"totalResults":18,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-12T04:48:58.996","vulnerabilities":[{"cve":{"id":"CVE-2025-65290","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:26.603","lastModified":"2026-06-17T09:55:36.697","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T16:46:09.908505Z","id":"CVE-2025-65290","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Certificate-Validation-Bypass.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65291","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:26.710","lastModified":"2026-06-17T09:55:36.850","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-07T16:58:50.112561Z","id":"CVE-2025-65291","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/CoAP-Certificate-Validation-Bypass.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65292","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:26.813","lastModified":"2026-06-17T09:55:37.000","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T16:44:51.671583Z","id":"CVE-2025-65292","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/DNS-Command-Injection.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65293","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:26.930","lastModified":"2026-06-17T09:55:37.153","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:13:44.105677Z","id":"CVE-2025-65293","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/QR-Command-Injection.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65294","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:27.033","lastModified":"2026-06-17T09:55:37.307","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:33:32.742284Z","id":"CVE-2025-65294","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/QR-Command-Injection.md","source":"cve@mitre.org","tags":["Not Applicable"]},{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/Undocumented-Remote-Execution.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65295","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:27.140","lastModified":"2026-06-17T09:55:37.467","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic methods that can be exploited to forge valid signatures, and exposes information through improperly initialized memory."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T20:40:55.908374Z","id":"CVE-2025-65295","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-326"},{"lang":"en","value":"CWE-347"},{"lang":"en","value":"CWE-457"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Firmware-Insecurity.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65296","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:27.257","lastModified":"2026-06-17T09:55:37.630","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:24:35.585541Z","id":"CVE-2025-65296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-476"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/JSON-NULL-Dereference.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-65297","sourceIdentifier":"cve@mitre.org","published":"2025-12-10T22:16:27.360","lastModified":"2026-06-17T09:55:37.787","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:08:54.539714Z","id":"CVE-2025-65297","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-5"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*","matchCriteriaId":"1DA5251B-FBDF-4020-B4AD-8735547D7BAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*","matchCriteriaId":"A94EB182-2F3B-42B2-935E-72936E6F8F33"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*","matchCriteriaId":"4B9661B9-D471-4110-995C-04D9165DEA1F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*","matchCriteriaId":"8BC51964-8CAB-4849-A383-0D7D1CA68EE2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*","matchCriteriaId":"CF91CB18-CE99-4A86-A94C-7136288E8C33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*","matchCriteriaId":"E823C290-E362-4BE0-9885-9A7B981134BC"}]}]}],"references":[{"url":"https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/Unauthorized-Data-Upload.md","source":"cve@mitre.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50082","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:31.707","lastModified":"2026-07-10T02:45:22.513","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of \"CWE-306: Missing Authentication for Critical Function\" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with CVE-2026-50083, CVE-2026-50084, and CVE-2026-50085, any otherwise-unauthenticated attacker could execute a full takeover of affected devices."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Cloud Developer Portal","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:53:19.154380Z","id":"CVE-2026-50082","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:cloud_developer_portal:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"8B859B38-0688-4DDB-B977-D6A1AF395DBE"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-dev-portal-auth-token-2026-50082","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50083","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:31.827","lastModified":"2026-07-09T17:44:57.073","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of \"CWE-798: Use of Hard-coded Credentials.\" This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Aquara IAM/SSO Gateway","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:55:58.127070Z","id":"CVE-2026-50083","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:iam\\/sso_gateway:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"0AF0F7C7-D5DF-4B11-A27F-924E2D1DF1E3"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-hardcoded-oauth-cve-2026-50083","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50084","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:31.940","lastModified":"2026-07-09T17:44:44.970","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of \"CWE-862: Missing Authorization\" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Cloud Production API","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:55:07.354028Z","id":"CVE-2026-50084","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:cloud_production_api:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"D802A96D-216F-43F9-BF68-5EE034D9811D"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-api-access-cve-2026-50084","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50085","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.060","lastModified":"2026-07-09T17:44:25.490","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of \"CWE-306: Missing Authentication for Critical Function\" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Board service","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:54:13.689198Z","id":"CVE-2026-50085","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:board_service:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"19B8F79D-9D4F-4918-8C55-082F943AFAA3"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-board-iot-insecure-debug-api-cve-2026-50085","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50086","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.187","lastModified":"2026-07-09T16:04:17.713","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of \"CWE-306: Missing Authentication for Critical Function\" and \"CWE-327: Use of a Broken or Risky Cryptographic Algorithm,\" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High)."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Aqara IAM/SSO Gateway","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:48:33.784868Z","id":"CVE-2026-50086","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-327"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:iam\\/sso_gateway:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"0AF0F7C7-D5DF-4B11-A27F-924E2D1DF1E3"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-unauth-aes-oracle-cve-2026-50086","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50087","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.297","lastModified":"2026-07-09T16:26:07.683","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of \"CWE-942: Permissive Cross-domain Policy with Untrusted Domains,\" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High)."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Aqara IAM/SSO Gateway","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:51:57.814157Z","id":"CVE-2026-50087","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-942"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:iam\\/sso_gateway:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"0AF0F7C7-D5DF-4B11-A27F-924E2D1DF1E3"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-iam-sso-cors-cve-2026-50087","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50088","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.403","lastModified":"2026-07-09T17:43:01.183","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of \"CWE-942: Permissive Cross-domain Policy with Untrusted Domains,\" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High)."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Aqara Developer Portal","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]},{"vendor":"Aqara","product":"Aqara Developer Test Portal","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:51:00.517874Z","id":"CVE-2026-50088","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-942"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:developer_portal:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"5700D2DE-752C-4D68-814A-2B908530B3AC"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-dev-portal-cors-cve-2026-50088","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50089","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.513","lastModified":"2026-07-09T17:41:17.783","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of \"CWE-601: URL Redirection to Untrusted Site,\" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Aqara IAM/SSO Gateway","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:50:04.675728Z","id":"CVE-2026-50089","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:iam\\/sso_gateway:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"0AF0F7C7-D5DF-4B11-A27F-924E2D1DF1E3"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-sso-open-redirect-cve-2026-50089","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50090","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.623","lastModified":"2026-07-09T17:41:07.727","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of \"CWE-1289: Improper Validation of Unsafe Equivalence in Input\" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N (9.3 Critical)."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"Cloud OAuth Authorization Endpoint","defaultStatus":"unaffected","versions":[{"version":"2026-04-20","lessThan":"0","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T15:49:22.517830Z","id":"CVE-2026-50090","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-1289"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:cloud_oauth_authorization_endpoint:2026-04-20:*:*:*:*:*:*:*","matchCriteriaId":"AF1FD493-5B7C-439E-9924-48B64E46416C"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-oauth-redirect-validation-bypass-cve-2026-50090","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-50091","sourceIdentifier":"44488dab-36db-4358-99f9-bc116477f914","published":"2026-06-12T16:16:32.737","lastModified":"2026-07-09T17:40:51.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of \"CWE-321: Use of Hard-coded Cryptographic Key\" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical)."}],"affected":[{"source":"44488dab-36db-4358-99f9-bc116477f914","affectedData":[{"vendor":"Aqara","product":"com.lumiunited.aqarahome","defaultStatus":"unaffected","versions":[{"version":"6.0.0","lessThan":"0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-12T16:22:49.247673Z","id":"CVE-2026-50091","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"44488dab-36db-4358-99f9-bc116477f914","type":"Secondary","description":[{"lang":"en","value":"CWE-321"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aqara:home:6.0.0:*:*:*:*:android:*:*","matchCriteriaId":"967E9F3A-6893-4330-B89D-A5A53120C492"}]}]}],"references":[{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.runzero.com/advisories/aqara-hardcoded-sdk-keys-cve-2026-50091","source":"44488dab-36db-4358-99f9-bc116477f914","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xn0tsa/theres-no-place-like-home","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}}]}