Executive brief
The Aqara Cloud Production API, which manages smart home devices like locks and cameras, contains a flaw that allows any registered developer to access other users' accounts. By using a valid developer token, an attacker could remotely control smart devices or view private data belonging to any customer on the platform. When combined with other vulnerabilities, this could allow an unauthorized person to take full control of a home's smart security system without needing a password.
Technical details
The vulnerability is a 'Missing Authorization' (CWE-862) flaw within the Aqara Cloud Production API. While the API uses an MD5-based signing primitive for request authentication, it fails to verify if the authenticated developer (Appid) has permission to access the specific user-scope endpoints or resources requested. An attacker with a valid developer token—which can be obtained for free—can perform read/write operations against arbitrary user accounts. This issue serves as a critical step in an exploit chain that enables unauthenticated remote takeover of IoT devices including smart locks and cameras. The vendor reportedly remediated the issue in April 2026.
Affected products
- Aqara Cloud Production API v3.0
Timeline
- 2026-03-13: disclosed: Initial researcher outreach to vendor
- 2026-04-08: patched: Vulnerabilities remediated by vendor
- 2026-04-20: other: Vendor acknowledged researcher reporting and confirmed fix
- 2026-06-12: advisory: Public disclosure