Impact
The Aqara Board service accepts arbitrary MQTT command payloads and forwards them to the platform’s HiveMQ broker without any authentication. This missing authentication allows an attacker to send any MQTT message that the broker will accept, enabling unauthorized control over the device. The vulnerability is classified as CWE‑306 and has a CVSS score of 8.6, indicating a high‑severity remote code execution risk. When used in conjunction with CVE-2026‑50082, 50083, and 50084, an attacker could fully take over the device.
Affected Systems
This flaw affects Aqara Board services hosted at op‑test.aqara.com. Detailed product or firmware versions were not provided, so administrators should verify all instances of the Aqara Board service that communicate with HiveMQ for the possibility of this insecure debug API.
Risk and Exploitability
The CVSS metric highlights the high likelihood of exploitation, with no authentication or user interaction required. Because the attack vector is through the open MQTT broker, an adversary can remotely send malicious commands from any network that reaches the broker. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of authentication poses significant risk for devices that rely on the Board service for operational commands.
OpenCVE Enrichment