Known Vulnerabilities for Aqara by Vendor
Listed below are 10 of the newest known vulnerabilities associated with "Aqara" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-50091 json | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-c... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50090 json | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to la... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50089 json | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50088 json | The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com)... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50087 json | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance ... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50086 json | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key wit... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50085 json | The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveM... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50084 json | The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any ... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50083 json | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798:... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-50082 json | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker... | Not Provided | 2026-06-12 | 2026-06-12 |