Skip to main content
Vulnerability Database/CVE-2025-65293

CVE-2025-65293: Aqara Camera Hub G3 Firmware RCE Vulnerability

CVE-2025-65293 is a command injection vulnerability in Aqara Camera Hub G3 Firmware that allows attackers to execute arbitrary commands with root privileges via malicious QR codes. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2025-65293 Overview

CVE-2025-65293 is a command injection vulnerability affecting the Aqara Camera Hub G3 running firmware version 4.1.9_0027. The device processes QR codes during setup and factory reset without properly sanitizing embedded content. An attacker who presents a crafted QR code to the camera can execute arbitrary commands with root privileges. Exploitation requires physical proximity and user interaction, since the victim must scan the malicious QR code during device provisioning. The flaw maps to [CWE-77: Improper Neutralization of Special Elements used in a Command].

Critical Impact

Successful exploitation yields root-level command execution on the camera, allowing full device takeover, credential theft, and pivoting into the local network.

Affected Products

  • Aqara Camera Hub G3 (hardware)
  • Aqara Camera Hub G3 firmware version 4.1.9_0027
  • Deployments performing initial setup or factory reset workflows that rely on QR code onboarding

Discovery Timeline

  • 2025-12-10 - CVE-2025-65293 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2025-65293

Vulnerability Analysis

The Aqara Camera Hub G3 uses QR codes to transfer configuration parameters, such as Wi-Fi credentials, to the device during onboarding and after factory reset. The firmware parses the decoded QR payload and passes fields into shell commands without proper neutralization of metacharacters. Attacker-supplied content is therefore interpreted by the underlying shell.

Because the QR handler runs in the context of the device's provisioning service, injected commands execute with root privileges. This allows the attacker to modify system binaries, plant persistence, exfiltrate video and audio streams, or use the camera as a foothold on the internal network. The attack does not require credentials or prior access to the device, but it does require the victim to scan the crafted code physically.

Root Cause

The root cause is improper input sanitization in the QR code parsing routine. Decoded fields are concatenated into shell command strings without escaping shell metacharacters such as ;, |, `, and $(). This design pattern places attacker-controlled data directly into a command interpreter, which is the canonical CWE-77 anti-pattern.

Attack Vector

The attack vector is physical. An attacker generates a QR code containing legitimate-looking provisioning data followed by shell metacharacters and injected commands. The attacker then convinces the victim to scan the code during initial setup or after a factory reset, for example by substituting a printed sticker, sharing a QR image, or leaving a rogue setup card. When the camera decodes the QR content, the appended commands execute as root.

Refer to the GitHub CVE Report: QR Command Injection for the full technical write-up and payload structure.

Detection Methods for CVE-2025-65293

Indicators of Compromise

  • Unexpected outbound network connections originating from the Aqara Camera Hub G3 shortly after setup or factory reset
  • New or modified files in writable firmware directories, or unexpected processes running as root on the device
  • Camera devices appearing on the network with modified firmware banners, altered service ports, or non-standard listening sockets

Detection Strategies

  • Monitor network segments hosting IoT devices for anomalous egress traffic from camera IP addresses, particularly to unknown external hosts
  • Inspect DHCP and ARP tables for Aqara devices that appear immediately after onboarding events and correlate them with unusual traffic
  • Where the device supports it, capture and review provisioning logs for QR payloads containing shell metacharacters such as ;, &&, |, $(, or backticks

Monitoring Recommendations

  • Segment IoT cameras onto a dedicated VLAN and log all north-south and east-west traffic for behavioral baselining
  • Alert on any interactive shell traffic patterns, reverse-shell signatures, or persistent outbound TLS connections from smart home devices
  • Track firmware version telemetry across the fleet to identify devices still running 4.1.9_0027

How to Mitigate CVE-2025-65293

Immediate Actions Required

  • Perform device setup and factory reset operations only in trusted physical environments using QR codes generated by the official Aqara application
  • Do not scan QR codes obtained from third parties, printed stickers of unknown origin, or shared images during camera provisioning
  • Inventory all Aqara Camera Hub G3 devices and identify units running firmware 4.1.9_0027

Patch Information

No vendor advisory or fixed firmware version is listed in the NVD entry for CVE-2025-65293 at the time of publication. Monitor Aqara's official support channels for a firmware release addressing the QR code parsing flaw, and apply the update as soon as it becomes available. The referenced GitHub CVE Report is the primary public source of technical detail.

Workarounds

  • Restrict who can physically interact with cameras during onboarding and factory reset workflows
  • Isolate affected cameras on a segmented network with strict egress filtering to limit the blast radius if a device is compromised
  • Disable or avoid factory reset procedures until patched firmware is deployed, and re-provision devices only from trusted QR sources
  • Decommission or replace devices that cannot be updated if they are deployed in sensitive environments

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.