CVE-2025-65293: Aqara Camera Hub g3 Firmware
Medium severity, CVSS 6.6. EPSS: 1.1% chance of exploitation in the next 30 days.
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
Affected products
- Aqara Camera Hub g3 Firmware: version 4.1.9_0027 only
Published 2025-12-10. Last modified 2026-09-25.