External risk intelligence

Aqara Hubs Vulnerable to Undocumented Remote Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-65294

The affected devices are smart home hubs intended for local network management. While they are not designed to be directly exposed to the public internet, IoT devices are frequently misconfigured or exposed via port forwarding or UPnP in residential deployments, making them plausibly reachable from the internet, though public exposure is not the intended or default configuration.

Code Injection

Aqara Hub M2 Firmware

4.3.6_00274.3.6_00254.1.9_0027

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Aqara Hub devices, including models like the Camera Hub G3, Hub M2, and Hub M3. The issue involves an undocumented remote access mechanism that allows for unrestricted remote command execution. This capability could potentially be exploited to gain unauthorized control over the affected devices.

  • Undocumented access allows remote command execution.
  • Critical vulnerability in smart home hubs.
  • Confirm relevance and exposure for smart home devices.

Attack Path

How an attacker could exploit the issue

An attacker could potentially leverage an undocumented remote access mechanism on Aqara Hub devices to execute arbitrary commands. This access bypasses normal authentication and could allow an attacker to take control of the device and any connected systems.

  • Network access required.
  • Undocumented remote access triggers execution.
  • Unrestricted command execution risk.

Live Threat

Current exploitation, exposure, and threat context

An undocumented remote access mechanism on Aqara Hub devices could allow an unauthenticated user to execute arbitrary commands remotely. This could affect system data and service behavior when these devices are reachable from a network.

  • Hub device system data.
  • Unrestricted remote command execution.
  • Compromised device functionality.

Operational Fix

Recommended remediation, mitigation, and detection steps

Aqara smart home hubs are likely managed by home users or potentially by IT teams in specific business contexts. The immediate priority is to determine the presence and reachability of these devices within your environment, identify their owners, and then assess the risk to plan for mitigation.

  • Identify device presence and reachability.
  • Confirm accountable device owner.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What are Aqara Hub devices?

Aqara Hubs like the Camera Hub G3, M2, and M3 serve as central controllers for smart home ecosystems. They manage connected devices, bridge communication between sensors and the network, and coordinate automation tasks. Because they act as the "brain" of a smart home, they require consistent network connectivity to function and integrate with various home automation platforms.

What is the weakness in CVE-2025-65294?

The vulnerability is categorized as CWE-94, or Improper Control of Generation of Code. In plain terms, this means the software contains a hidden, undocumented feature that allows external commands to be sent to the device and executed without proper authorization. It effectively provides a back door for performing unauthorized actions on the hub.

How can an attacker trigger this vulnerability?

An attacker triggers this by reaching the device over a network and interacting with the undocumented access mechanism. This bug does not require an attacker to have pre-existing login credentials or local physical access. Simply reaching the interface allows the execution of arbitrary commands, bypassing standard authentication checks entirely.

Do I need to worry about this if my hub is internal?

According to Halo Surface Signal, these devices are designed for local network management, not direct internet exposure. However, they are often reachable from the internet due to common issues like port forwarding or UPnP configurations. If your hub is reachable from outside your local network, the risk of exploitation is significantly higher.

How should I respond to this threat?

Start by identifying all Aqara Hubs within your network to understand where they are placed and who is responsible for them. Once identified, evaluate if these devices are inadvertently exposed to the internet. If you find them exposed, restrict their network access immediately to ensure they remain within your secure, private local environment.

References