Junglewise Threat Intelligence

CVE-2025-65293: Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges throu

CVE-2025-65293 · Severity: medium · CVSS 6.6 · Published 2025-12-10

Technologies: Aqara Camera Hub G3 Firmware, Aqara Camera Hub G3. Vendors: Aqara.

Executive brief

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

Affected products

  • Aqara camera_hub_g3_firmware
  • Aqara camera_hub_g3

Related threats