Aqara manufactures a focused line of smart-home hub and camera devices that serve as control and connectivity points for home-automation networks, concentrating its vulnerability footprint across firmware and hub products. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes centered on cryptographic validation, command and code injection, and signature verification that are characteristic of embedded networked devices handling authentication and local command processing. Defenders managing Aqara deployments should prioritize firmware updates for hub and camera products; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aqara over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50086CRITICAL The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: M | Jun 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-50085CRITICAL The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of | Jun 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-50083CRITICAL The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estim | Jun 12, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-65294CRITICAL Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command | Dec 10, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-50091HIGH Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-3 | Jun 12, 2026 | 7.4 | 32 | NO | NO |
CVE-2026-50090MEDIUM The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of | Jun 12, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-50087MEDIUM The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrus | Jun 12, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-50084MEDIUM The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Autho | Jun 12, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-50089MEDIUM The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1 | Jun 12, 2026 | 6.1 | 26 | NO | NO |
CVE-2025-65295HIGH Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install maliciou | Dec 10, 2025 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aqara.
Media articles that mention a CVE ID that affects a product developed by Aqara — matched by CVE ID, not by vendor name.