Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meari
Meari com.meari.sdk |
|
| Vendors & Products |
Meari
Meari com.meari.sdk |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys. | |
| Title | Meari SDK hardcoded cryptographic keys | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-05-11T18:15:45.783Z
Reserved: 2026-03-19T00:27:05.987Z
Link: CVE-2026-33362
Updated: 2026-05-11T18:15:42.048Z
Status : Deferred
Published: 2026-05-11T17:16:31.083
Modified: 2026-05-13T15:36:30.533
Link: CVE-2026-33362
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:22:56Z