← IoT Privacy Database

Aqara Smart Hub

Aqara (Lumi United Technology) · Camera / Doorbell

✓ Reviewed

2.6Surveillance
Index
Policy — what its policy permitsB
Evidence — what research provesC

Sensor/camera hub from Aqara (Lumi United, China) coordinating Zigbee sensors, cameras, and locks. Cloud-linked automations via the Aqara Home account, with support for local automations and Apple HomeKit local mode. Camera-hub variants (G-series) add a microphone and camera. In Dec 2025 NIST published a cluster of hub CVEs: CVE-2025-65297 (CVSS 7.5) — Hub M2/M3 and Camera Hub G3 automatically upload unencrypted sensitive information without disclosure or opt-out, exposing occupancy patterns and device inventories to anyone on the network path — plus CVE-2025-65295 (CVSS 8.1), an OTA firmware-signature bypass enabling persistent malicious firmware, and CVE-2025-65291, a TLS certificate-validation bypass.

Why this rating

POLICY 85: start 100; sensitive-collection -15 (device family captures camera audio/video on G-series camera hubs, fingerprint biometrics for ecosystem door access, and app-side access to GPS location); policy-vagueness -7 (the governing Aqara Home GDPR app policy is silent on whether personal data is sold and describes no law-enforcement/government disclosure process). Bonus local-processing-mode +7 (supports local automations and Apple HomeKit local mode). 100-15-7+7=85. Not deducted for no-deletion-right (the GDPR app policy grants deletion via account cancellation and a Clear Logs function), for indefinite-retention (policy states one-year log retention and purpose-based retention otherwise), or for data-sale (no evidence of actual sale; only non-sensitive sharing with advertising providers, with sensitive data not shared without explicit consent). EVIDENCE 65: start 100; undisclosed-collection -25 (CVE-2025-65297: hubs silently upload sensitive info unencrypted, undocumented, no opt-out; CVSS 7.5 HIGH) and security-negligence -10 (CVE-2025-65295: OTA firmware update accepts unsigned/forgeable firmware allowing persistent malicious firmware, CVSS 8.1 HIGH; part of the same disclosure that also includes CVE-2025-65291 TLS certificate-validation bypass). 100-25-10=65. Device is studied - a December 2025 primary-sourced disclosure cluster of multiple confirmed CVEs across these hubs - so it clears the unstudied (<=60) cap; grade C reflects multiple recent, confirmed privacy+security failures rather than a clean, heavily-litigated, or breached record.

What it is

Manufacturer
Aqara (Lumi United Technology)
Category
Camera / Doorbell
Model years
2018-present
Market status
Current
Companion app
Aqara Home

The evidence 3

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Vulnerability · NIST National Vulnerability Database (CVE assigned by MITRE; CVSS provided by CISA-ADP) · 2025-12-10

    Aqara Camera Hub G3 (4.1.9_0027), Hub M2 (4.3.6_0027), and Hub M3 (4.3.6_0025) automatically collect and upload unencrypted sensitive information without user knowledge or manufacturer disclosure; CWE-5 data transmission without encryption; CVSS v3.1 base 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H). Anyone on the network path can passively read occupancy patterns and device inventories.

    Why it matters here: Confirms undisclosed-collection on the evidence axis: silent, undocumented, opt-out-less upload of sensitive hub telemetry in cleartext.

  2. Vulnerability · NIST National Vulnerability Database (CVE assigned by MITRE; CVSS provided by CISA-ADP) · 2025-12-10

    Aqara Camera Hub G3 (4.1.9_0027), Hub M2 (4.3.6_0027), and Hub M3 (4.3.6_0025) fail to validate firmware signatures during OTA updates and rely on weak cryptography allowing signature forgery, plus information exposure from uninitialized memory (CWE-347/CWE-326/CWE-457); CVSS v3.1 base 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Exploitation allows installing persistent malicious firmware on the hub and connected accessories.

    Why it matters here: Grounds the security-negligence deduction with a distinct, confirmed engineering failure; part of the same Dec 2025 disclosure cluster as CVE-2025-65297 and CVE-2025-65291 (TLS certificate-validation bypass).

  3. Privacy policy · Aqara (Lumi United Technology) · 2026-03-20

    Vendor primary source; effective 20 March 2026 (accessed 2026-07-21). GDPR privacy policy governing the Aqara Home app. States EU personal data is processed on a server in Frankfurt, Germany, with transfers to/from China only on express consent or contract necessity; grants data-subject rights including deletion via account cancellation and a Clear Logs function; states log data retained one year and other data retained until purpose achieved or account deleted; accesses GPS/Bluetooth/WLAN but collects precise location only with separate consent; references cameras and fingerprint/biometric door access. Gaps: no explicit statement that personal data is not sold (non-sensitive data may be shared with advertising providers) and no described law-enforcement/government disclosure process.

    Why it matters here: Basis for the policy-axis sensitive-collection and policy-vagueness (data-sale + law-enforcement silence) deductions, and for the local-processing/EU-localization and deletion-rights mitigations.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database