cbcvebase.
CVE-2025-65296
published 2025-12-10

CVE-2025-65296: NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable…

PriorityP423medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.25%
16.3th percentile
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

Affected

3 ranges
VendorProductVersion rangeFixed in
aqaracamera_hub_g3_firmware
aqarahub_m2_firmware
aqarahub_m3_firmware
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.