Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Aqara — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting Aqara. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates known vulnerabilities associated with the vendor Aqara, focusing on software weaknesses and security advisories. It collects data regarding various security flaws, including remote code execution, information disclosure, and authentication bypass issues affecting Aqara’s smart home ecosystem. The database covers vulnerabilities identified and disclosed from 2018 through the current year, ensuring a comprehensive view of historical and recent security incidents. Here, security researchers and users can track official vendor advisories to stay informed about patches and mitigation strategies. You can also understand the prevalence and impact of specific weakness classes within the company’s product line, analyzing trends in reported bugs over time. Additionally, users can look up a specific product’s vulnerability history to assess its security posture and update firmware accordingly. This resource serves as a centralized reference for evaluating risks associated with Aqara devices, including smart hubs, sensors, and lighting controllers. By consolidating these data points, the page facilitates better risk management and informed decision-making for both enterprise administrators and individual consumers. The information is derived from public security databases, vendor release notes, and industry reports, providing a reliable basis for security analysis without endorsing any particular vendor or product.

CVE IDTitleCVSSSeverityPublished
CVE-2026-50091 Aqara Home Android SDK hardcoded keys — com.lumiunited.aqarahomeCWE-321 9.1 Critical2026-06-12
CVE-2026-50090 Aqara OAuth redirect_uri validation bypass — Cloud OAuth Authorization EndpointCWE-1289 9.3 Critical2026-06-12
CVE-2026-50089 Aqara IAM/SSO Gateway open redirect — Aqara IAM/SSO GatewayCWE-601 6.1 Medium2026-06-12
CVE-2026-50088 Aqara Developer Portal cross-origin resource sharing — Aqara Developer PortalCWE-942 8.2 High2026-06-12
CVE-2026-50087 Aqara IAM/SSO Gateway cross-origin resource sharing — Aqara IAM/SSO GatewayCWE-942 8.2 High2026-06-12
CVE-2026-50086 Aqara unauthenticated AES oracle — Aqara IAM/SSO GatewayCWE-327 10.0 Critical2026-06-12
CVE-2026-50085 Aqara Board IoT insecure debug API — Board serviceCWE-306 8.6 High2026-06-12
CVE-2026-50084 Aqara API cross-account access — Cloud Production APICWE-862 9.6 Critical2026-06-12
CVE-2026-50083 Aqara hardcoded OAuth client credentials — Aquara IAM/SSO GatewayCWE-798 9.1 Critical2026-06-12
CVE-2026-50082 Aqara Developer Portal insecure authentication token — Cloud Developer PortalCWE-306 6.5 Medium2026-06-12

This page lists every published CVE security advisory associated with Aqara. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.