Aqara
10 known vulnerabilities
Top Products
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att
Frequently Asked Questions
How many CVEs affect Aqara?
Aqara has 10 CVE records in our database, including 5 critical and 3 high severity vulnerabilities.
What are the most severe Aqara vulnerabilities?
Aqara has 5 critical severity (CVSS 9.0+) and 3 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Aqara vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Aqara products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Aqara Vulnerabilities
CyberStrike scans your infrastructure for Aqara vulnerabilities and provides real-time remediation guidance.
Get Started