MEDIUM · 6.6

CVE-2025-65293

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

Vulnerability Description

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AqaraCamera Hub G3 Firmware4.1.9_0027
AqaraCamera Hub G3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-65293?

CVE-2025-65293 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

How severe is CVE-2025-65293?

CVE-2025-65293 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-65293?

Check the references section above for vendor advisories and patch information. Affected products include: Aqara Camera Hub G3 Firmware, Aqara Camera Hub G3.