Junglewise Threat Intelligence

CVE-2026-50091: Aqara Home Android hard-coded cryptographic keys in liblumidevsdk.so

CVE-2026-50091 · Severity: critical · CVSS 9.1 · Published 2026-06-12

Vendors: Aqara.

Executive brief

The Aqara Home Android application and its associated developer tools contain permanent, unchangeable security keys used to protect smart home devices. An attacker who extracts these keys can potentially intercept private camera feeds, forge commands to smart locks, and impersonate legitimate devices. This impacts the privacy and physical security of users relying on the Aqara smart home ecosystem.

Technical details

The vulnerability stems from the use of hard-coded cryptographic keys within the 'liblumidevsdk.so' native library in Aqara Home Android version 6.0.0. These static keys are used for camera authentication signatures, device pairing payloads, and general content encryption between the client and the Aqara platform. Because the keys are identical across all installations and white-label variants, they can be recovered via static analysis (strings) of the APK. An attacker can leverage these keys to decrypt intercepted traffic or forge authentication signatures to gain unauthorized access to IoT devices like cameras and hubs. Fixes were reportedly coordinated with the vendor, though some issues remained as of the disclosure date.

Affected products

  • Aqara Aqara Home Android 6.0.0

Timeline

  • 2026-03-13: other: Vulnerability discovered and initial vendor outreach
  • 2026-04-08: patched: Vendor remediated various findings
  • 2026-06-12: disclosed: Public disclosure

References