Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aqara
Aqara camera Hub G3 Aqara hub M2 Aqara hub M3 |
|
| Vendors & Products |
Aqara
Aqara camera Hub G3 Aqara hub M2 Aqara hub M3 |
Thu, 11 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-11T16:46:12.322Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65290
Updated: 2025-12-11T16:46:06.846Z
Status : Received
Published: 2025-12-10T22:16:26.603
Modified: 2025-12-11T17:15:57.407
Link: CVE-2025-65290
No data.
OpenCVE Enrichment
Updated: 2025-12-11T21:38:01Z