Aqara Cloud Developer Portal是美国Aqara公司的一个云计算平台。 Aqara Cloud Developer Portal存在授权问题漏洞,该漏洞源于缺少关键功能认证,向任意电子邮件地址颁发开发者令牌,可能导致未经验证的攻击者结合其他漏洞完全接管受影响设备。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Aqara | Cloud Developer Portal | 2026-04-20< 0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Aqara | Cloud Developer Portal | 2026-04-20 ~ 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50086 | 10.0 CRITICAL | Aqara unauthenticated AES oracle |
| CVE-2026-50084 | 9.6 CRITICAL | Aqara API cross-account access |
| CVE-2026-50090 | 9.3 CRITICAL | Aqara OAuth redirect_uri validation bypass |
| CVE-2026-50083 | 9.1 CRITICAL | Aqara hardcoded OAuth client credentials |
| CVE-2026-50091 | 9.1 CRITICAL | Aqara Home Android SDK hardcoded keys |
| CVE-2026-50085 | 8.6 HIGH | Aqara Board IoT insecure debug API |
| CVE-2026-50087 | 8.2 HIGH | Aqara IAM/SSO Gateway cross-origin resource sharing |
| CVE-2026-50088 | 8.2 HIGH | Aqara Developer Portal cross-origin resource sharing |
| CVE-2026-50089 | 6.1 MEDIUM | Aqara IAM/SSO Gateway open redirect |
No comments yet