CVE-2026-33362 PUBLISHED

Meari SDK hardcoded cryptographic keys

Assigner: runZero
Reserved: 19.03.2026 Published: 11.05.2026 Updated: 11.05.2026

In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Meari
Product com.meari.sdk
Versions Default: unaffected
  • Version firmID=8 is affected

Credits

  • Sammy Azdoufal finder
  • Tod Beardsley of runZero, Inc. coordinator

References

Problem Types

  • CWE-321 Use of Hard-coded Cryptographic Key CWE