Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).
The liblumidevsdk.so library included in Aqara Home 6.0.0 stores cryptographic keys directly in the application's binary code (CWE-321: Use of Hard-coded Cryptographic Key). An attacker can extract these keys through static analysis of the .so file and then use them to decrypt or sign communication with the system infrastructure. Since the same keys are present in all white-label products using this library, the scale of potential impact encompasses multiple brands and applications simultaneously.
An attacker can gain access to sensitive data transmitted by the application (e.g., authentication credentials, tokens, IoT device information) and manipulate communication between the application and the server, leading to a violation of system integrity and confidentiality.
Patches available from the manufacturer should be applied according to the references. Users should update the Aqara Home application to a version free of hard-coded keys. White-label product vendors using liblumidevsdk.so should verify whether their version of the library is vulnerable and update the embedded SDK.
Aqara Home on Android (com.lumiunited.aqarahome) version 6.0.0 and white-label applications embedding the same liblumidevsdk.so library
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NAqara Home
APPAqara6.0.0
Related vulnerabilities
Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)
Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący
Aqara IAM/SSO Gateway — zakodowane na stałe dane uwierzytelniające OAuth
Brak autoryzacji w Aqara Cloud Production API umożliwia przejęcie konta
Aqara Hub — nieudokumentowany mechanizm zdalnego wykonania poleceń (RCE)