Aqara IAM/SSO Gateway是美国Aqara公司的一个身份认证与访问管理网关。 Aqara IAM/SSO Gateway存在输入验证错误漏洞,该漏洞源于开放重定向,可能导致设置钓鱼攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Aqara | Aqara IAM/SSO Gateway | 2026-04-20< 0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Aqara | Aqara IAM/SSO Gateway | 2026-04-20 ~ 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50086 | 10.0 CRITICAL | Aqara unauthenticated AES oracle |
| CVE-2026-50084 | 9.6 CRITICAL | Aqara API cross-account access |
| CVE-2026-50090 | 9.3 CRITICAL | Aqara OAuth redirect_uri validation bypass |
| CVE-2026-50083 | 9.1 CRITICAL | Aqara hardcoded OAuth client credentials |
| CVE-2026-50091 | 9.1 CRITICAL | Aqara Home Android SDK hardcoded keys |
| CVE-2026-50085 | 8.6 HIGH | Aqara Board IoT insecure debug API |
| CVE-2026-50087 | 8.2 HIGH | Aqara IAM/SSO Gateway cross-origin resource sharing |
| CVE-2026-50088 | 8.2 HIGH | Aqara Developer Portal cross-origin resource sharing |
| CVE-2026-50082 | 6.5 MEDIUM | Aqara Developer Portal insecure authentication token |
No comments yet