Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3...
High severity
Unreviewed
Published
Dec 11, 2025
to the GitHub Advisory Database
•
Updated Jan 7, 2026
Description
Published by the National Vulnerability Database
Dec 10, 2025
Published to the GitHub Advisory Database
Dec 11, 2025
Last updated
Jan 7, 2026
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
References