Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aqara

First CVE: Dec 10, 2025Active for: 1 yearTotal CVEs: 18
30.2
VTI Score
Low

Aqara manufactures a focused line of smart-home hub and camera devices that serve as control and connectivity points for home-automation networks, concentrating its vulnerability footprint across firmware and hub products. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes centered on cryptographic validation, command and code injection, and signature verification that are characteristic of embedded networked devices handling authentication and local command processing. Defenders managing Aqara deployments should prioritize firmware updates for hub and camera products; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aqara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2025
7 months ago
Most Recent CVE
Jun 12, 2026
42 days ago

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-50086CRITICAL
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: M
Jun 12, 20269.840NONO
CVE-2026-50085CRITICAL
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of
Jun 12, 20269.840NONO
CVE-2026-50083CRITICAL
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estim
Jun 12, 20269.838NONO
CVE-2025-65294CRITICAL
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command
Dec 10, 20259.834NONO
CVE-2026-50091HIGH
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-3
Jun 12, 20267.432NONO
CVE-2026-50090MEDIUM
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of
Jun 12, 20266.130NONO
CVE-2026-50087MEDIUM
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrus
Jun 12, 20266.130NONO
CVE-2026-50084MEDIUM
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Autho
Jun 12, 20266.530NONO
CVE-2026-50089MEDIUM
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1
Jun 12, 20266.126NONO
CVE-2025-65295HIGH
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install maliciou
Dec 10, 20258.126NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
44%
33%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.6%)
Network15 (83.3%)
Unknown0 (0.0%)
Physical1 (5.6%)
Adjacent Network1 (5.6%)
Attack Complexity
Low14 (77.8%)
High4 (22.2%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low2 (11.1%)
High0 (0.0%)
None16 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aqara.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aqara — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aqara's Products

View all 2 CNAs →

Top CWEs