Aqara Hub devices including Hub M2 4.3.60027, Hub M3 4.3.60025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.3.6_0027"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.3.6_0025"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.1.9_0027"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65291.json"