Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aqara
Aqara com.lumiunited.aqarahome |
|
| Vendors & Products |
Aqara
Aqara com.lumiunited.aqarahome |
Fri, 12 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). | |
| Title | Aqara Home Android SDK hardcoded keys | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-06-12T16:22:58.685Z
Reserved: 2026-06-03T14:25:34.982Z
Link: CVE-2026-50091
Updated: 2026-06-12T16:22:41.112Z
Status : Awaiting Analysis
Published: 2026-06-12T16:16:32.737
Modified: 2026-06-12T17:16:26.283
Link: CVE-2026-50091
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:19:38Z