Aqara Hub and Camera Hub Undocumented Remote Command Execution Vulnerability

Vulnerability

A vulnerability exists in Aqara Hub devices, including Camera Hub G3, Hub M2, and Hub M3, allowing unrestricted remote command execution with root privileges. This backdoor access is facilitated through an undocumented mechanism via CoAP commands, enabling execution of arbitrary shell commands on the device. The vulnerability arises from improper input sanitization when processing QR code data, which can be exploited during device setup or factory reset operations.

Impact

Exploitation of this vulnerability allows unauthorized remote code execution with root privileges on the affected devices.

Reproduction

The vulnerability can be reproduced by sending a CoAP request to the '/lumi/gw/rpc' endpoint with a JSON payload that includes the 'system_run' or 'system_command' methods. The 'system_run' method executes commands in the background without returning output, while 'system_command' executes commands synchronously and captures the output, which is returned in the response.

Remediation

Aqara has released firmware updates for the affected Hub M2 and M3 models, which include the necessary patches. For the Camera Hub G3, a compatible firmware version has also been released.

Added: Dec 10, 2025, 10:26 PM
Updated: Dec 10, 2025, 10:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.