Junglewise Threat Intelligence

CVE-2026-33357: Meari IoT SDK missing authorization in OpenAPI device status endpoint

CVE-2026-33357 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Meari IoT SDK. Vendors: Meari.

Executive brief

A security flaw in the software used by Meari, CloudEdge, and Arenti smart cameras allows unauthorized individuals to discover the physical network location (WAN IP address) of any device. This information can be used to geolocate users and their homes, posing a significant privacy and stalking risk. The issue stems from a failure in the manufacturer's cloud servers to properly verify who is requesting device status information.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Meari OpenAPI endpoint 'GET /openapi/device/status' at openapi-euce.mearicloud.com. The API fails to perform adequate server-side authorization checks, allowing any network-based attacker to query the status of arbitrary devices. While client applications like CloudEdge and Arenti use a static signing key that simplifies request forging, the primary issue is the lack of access control on the server. Attackers can exploit this to retrieve WAN IP addresses, which can be used for geolocation or targeted network attacks. This vulnerability is particularly potent when chained with other flaws (like CVE-2026-33356) to identify valid device IDs via MQTT traffic.

Affected products

  • Meari IoT SDK (com.meari.sdk) <= 1.8.x
  • Meari CloudEdge 5.5.0 build 220
  • Meari Arenti 1.8.1 build 220

Timeline

  • 2026-03-11: disclosed: Issues identified and disclosed to vendor
  • 2026-04-03: other: Opened VINCE Case VU#579666 with CISA
  • 2026-05-11: advisory: Public disclosure of vulnerability

References

Related threats