NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
| Software | From | Fixed in |
|---|---|---|
| aqara / hub_m2_firmware | 4.3.6_0027 | 4.3.6_0027.x |
| aqara / hub_m3_firmware | 4.3.6_0025 | 4.3.6_0025.x |
| aqara / camera_hub_g3_firmware | 4.1.9_0027 | 4.1.9_0027.x |