CVE List

CVE-2025-65297

Critical 7.5

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.

Published December 10, 2025.

Affected software

Get alerts for Aqara Hub M3 Firmware

Reference links