Skip to main content
Vulnerability Database/CVE-2025-65296

CVE-2025-65296: Aqara Hub M2 Firmware DOS Vulnerability

CVE-2025-65296 is a NULL-pointer dereference denial-of-service vulnerability in Aqara Hub M2, Hub M3, and Camera Hub G3 firmware affecting JSON processing. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2025-65296 Overview

CVE-2025-65296 affects multiple Aqara smart home hub products through NULL-pointer dereference flaws in their JSON processing routines. An attacker on the adjacent network can send malformed JSON input to the affected devices to trigger a crash. The resulting denial-of-service condition disrupts the hub's availability and the smart home automation services it provides. The vulnerability is tracked as CWE-476: NULL Pointer Dereference and impacts firmware versions shipped on the Hub M2, Hub M3, and Camera Hub G3.

Critical Impact

Adjacent-network attackers can crash Aqara Hub M2, Hub M3, and Camera Hub G3 devices by sending malformed JSON, disrupting smart home functions and connected camera feeds.

Affected Products

  • Aqara Hub M2 firmware 4.3.6_0027
  • Aqara Hub M3 firmware 4.3.6_0025
  • Aqara Camera Hub G3 firmware 4.1.9_0027

Discovery Timeline

  • 2025-12-10 - CVE-2025-65296 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2025-65296

Vulnerability Analysis

The flaw sits in the JSON parsing path used by the affected Aqara hub firmware. When the device receives crafted JSON input over the local network, the parser dereferences a pointer that was never assigned a valid object. The process servicing the request terminates, taking local hub functionality with it until the device recovers or is rebooted.

Because the attack vector is Adjacent Network, an attacker must share a local network segment with the target hub, such as the home Wi-Fi or a compromised IoT VLAN. No authentication or user interaction is required. The impact is limited to availability — the attacker cannot read device data or alter configuration through this flaw.

For Camera Hub G3 users, the crash can interrupt live and recorded video streams. For Hub M2 and Hub M3 users, it can halt Zigbee automation and routines that depend on the hub as the local controller.

Root Cause

The JSON processing code does not validate that required fields or sub-objects exist before dereferencing them. When a malformed JSON payload lacks an expected key or supplies an unexpected type, the resulting NULL pointer is accessed, causing a segmentation fault. This pattern is consistent with CWE-476.

Attack Vector

An attacker with access to the same local network as the hub transmits malformed JSON to a listening service on the device. Repeated requests sustain the denial-of-service condition. Technical details and reproduction steps are published in the researcher's GitHub PoC Report.

Detection Methods for CVE-2025-65296

Indicators of Compromise

  • Repeated unexpected reboots or service restarts on Aqara Hub M2, Hub M3, or Camera Hub G3 devices.
  • Loss of connectivity to Zigbee child devices or camera streams coinciding with malformed traffic on the local segment.
  • Unexplained bursts of inbound JSON payloads to the hub from untrusted hosts on the LAN or Wi-Fi.

Detection Strategies

  • Monitor network traffic to Aqara hubs for malformed or truncated JSON payloads targeting the device's local API ports.
  • Correlate hub availability gaps with network capture data on the IoT VLAN to identify adjacent-network abuse.
  • Alert on repeated TCP resets or connection terminations from the hub's service port, which can indicate parser crashes.

Monitoring Recommendations

  • Enable syslog or cloud event forwarding from Aqara devices where supported and watch for crash and restart events.
  • Use network sensors on IoT segments to baseline normal JSON API traffic and flag anomalous content lengths or structures.
  • Track Wi-Fi association logs for unknown devices appearing on the same subnet as smart home hubs.

How to Mitigate CVE-2025-65296

Immediate Actions Required

  • Isolate Aqara Hub M2, Hub M3, and Camera Hub G3 devices on a dedicated IoT VLAN or guest Wi-Fi, separated from user and management networks.
  • Restrict inbound local-network access to the hubs so only trusted automation controllers and the Aqara mobile app can reach them.
  • Audit all devices on the same segment and remove or quarantine any untrusted hosts that could issue malformed JSON.

Patch Information

No vendor advisory URL is published in the NVD record at the time of writing. Monitor Aqara's firmware release notes for updates beyond 4.3.6_0027 (Hub M2), 4.3.6_0025 (Hub M3), and 4.1.9_0027 (Camera Hub G3), and apply firmware updates as soon as they are released. Refer to the researcher's GitHub PoC Report for ongoing status.

Workarounds

  • Block or rate-limit untrusted inbound traffic to the hub's JSON API port using the local router or firewall.
  • Disable or firewall off any locally exposed management interfaces not required for day-to-day operation.
  • Automate periodic availability checks and power-cycle procedures so a crashed hub recovers quickly if abused.
bash
# Example: isolate Aqara hubs on an IoT VLAN and restrict access
# (adapt to your router/firewall syntax)

# Allow only the management host and Aqara cloud to reach the hub
iptables -A FORWARD -s 192.168.50.10 -d 192.168.60.0/24 -p tcp --dport 9898 -j ACCEPT
iptables -A FORWARD -d 192.168.60.0/24 -p tcp --dport 9898 -j DROP

# Drop malformed inbound traffic patterns at the IoT VLAN boundary
iptables -A FORWARD -d 192.168.60.0/24 -m length --length 0:16 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.