Executive brief
The Aqara IAM/SSO Gateway, a service used for managing user identities and access to smart home devices, contains hardcoded login credentials. An attacker can use these credentials to gain unauthorized access to the identity management system. When combined with other vulnerabilities, this could allow a remote attacker to take full control of Aqara smart locks, cameras, and hubs without needing a password.
Technical details
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) contains hardcoded OAuth client credentials (client_id 'test1' and client_secret '123456') that are accepted by the platform. An unauthenticated remote attacker can use these credentials via the /iam/oauthToken/openapi/client/token endpoint to obtain an access token with 'scope=all'. These tokens are long-lived and do not expire upon password changes. This vulnerability serves as a critical step in an exploit chain (including CVE-2026-50082, CVE-2026-50084, and CVE-2026-50085) that enables full remote takeover of IoT devices on the Aqara platform. The vendor reportedly remediated the issue in April 2026.
Affected products
- Aqara IAM/SSO Gateway gw-builder.aqara.com
Timeline
- 2026-03-13: disclosed: Researcher initiated outreach to vendor
- 2026-04-08: patched: Vendor remediated various findings
- 2026-04-20: other: Vendor acknowledged report and stated issue was fixed
- 2026-06-12: advisory: Public disclosure