VYPR

Aqara Board

by Runzero

CVEs (1)

  • CVE-2026-50085HigJun 12, 2026
    risk 0.56cvss 8.6epss

    The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS…