Vulnerability Description
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aqara | Camera Hub G3 Firmware | 4.1.9_0027 |
| Aqara | Camera Hub G3 | - |
Related Weaknesses (CWE)
References
- https://github.com/Chapoly1305/myCVEReports/blob/main/Aqara/QR-Command-InjectionExploitThird Party Advisory
FAQ
What is CVE-2025-65293?
CVE-2025-65293 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
How severe is CVE-2025-65293?
CVE-2025-65293 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65293?
Check the references section above for vendor advisories and patch information. Affected products include: Aqara Camera Hub G3 Firmware, Aqara Camera Hub G3.