CRITICAL🇵🇱 Wersja polska

CVE-2026-50091

CVSS 9.1v3.1pub. 2026-06-12upd. 2026-07-09

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).

🤖 AI Analysis
How it works

The liblumidevsdk.so library included in Aqara Home 6.0.0 stores cryptographic keys directly in the application's binary code (CWE-321: Use of Hard-coded Cryptographic Key). An attacker can extract these keys through static analysis of the .so file and then use them to decrypt or sign communication with the system infrastructure. Since the same keys are present in all white-label products using this library, the scale of potential impact encompasses multiple brands and applications simultaneously.

Impact

An attacker can gain access to sensitive data transmitted by the application (e.g., authentication credentials, tokens, IoT device information) and manipulate communication between the application and the server, leading to a violation of system integrity and confidentiality.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Users should update the Aqara Home application to a version free of hard-coded keys. White-label product vendors using liblumidevsdk.so should verify whether their version of the library is vulnerable and update the embedded SDK.

Who is affected

Aqara Home on Android (com.lumiunited.aqarahome) version 6.0.0 and white-label applications embedding the same liblumidevsdk.so library

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Aqara Home

    APP
    Aqara
    6.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50090CRITICAL9.3PL ✓same vendor

Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)

CVE-2026-50086CRITICAL10.0PL ✓same vendor

Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący

CVE-2026-50083CRITICAL9.1PL ✓same vendor

Aqara IAM/SSO Gateway — zakodowane na stałe dane uwierzytelniające OAuth

CVE-2026-50084CRITICAL9.6PL ✓same vendor

Brak autoryzacji w Aqara Cloud Production API umożliwia przejęcie konta

CVE-2025-65294CRITICAL9.8PL ✓same vendor

Aqara Hub — nieudokumentowany mechanizm zdalnego wykonania poleceń (RCE)