CVE-2025-65295
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic methods that can be exploited to forge valid signatures, and exposes information through improperly initialized memory.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1195Supply Chain Compromiseinitial access85 % - Impacto principal
T1553.006Code Signing Policy Modificationdefense impairment90 % - Impacto secundario
T1059Command and Scripting Interpreterexecution75 %
Proceso de actualización de firmware sin validación de firmas (CWE-347) en dispositivos Aqara permite inyectar firmware malicioso. T1195 por cadena de suministro (actualización comprometida); T1553.006 por desactivación de verificación de código; ejecución de código arbitrario en el dispositivo comp
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (3)
CWE
- CWE-326, CWE-347, CWE-457
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-65295",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-65295",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-11T20:40:55.908374Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2025-12-10T22:16:27.140",
"references": [
{
"url": "https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/OTA-Firmware-Insecurity.md",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-326"
},
{
"lang": "en",
"value": "CWE-347"
},
{
"lang": "en",
"value": "CWE-457"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic methods that can be exploited to forge valid signatures, and exposes information through improperly initialized memory."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades en el proceso de actualización del firmware de Aqara Hub en los dispositivos Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027 y Hub M3 4.3.6_0025, permiten a los atacantes instalar firmware malicioso sin la verificación adecuada. El dispositivo no valida las firmas del firmware durante las actualizaciones, utiliza métodos criptográficos obsoletos que pueden ser explotados para falsificar firmas válidas, y expone información a través de memoria inicializada incorrectamente."
}
],
"lastModified": "2026-09-25T23:10:00.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:aqara:hub_m2_firmware:4.3.6_0027:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DA5251B-FBDF-4020-B4AD-8735547D7BAB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:aqara:hub_m2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A94EB182-2F3B-42B2-935E-72936E6F8F33"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:aqara:hub_m3_firmware:4.3.6_0025:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B9661B9-D471-4110-995C-04D9165DEA1F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:aqara:hub_m3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8BC51964-8CAB-4849-A383-0D7D1CA68EE2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:aqara:camera_hub_g3_firmware:4.1.9_0027:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF91CB18-CE99-4A86-A94C-7136288E8C33"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:aqara:camera_hub_g3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E823C290-E362-4BE0-9885-9A7B981134BC"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}