Embedded IoT SDK Vulnerability in CloudEdge and Arenti Products
CVE-2026-33362

8.6HIGH

Key Information:

Vendor

Meari

Vendor
CVE Published:
11 May 2026

What is CVE-2026-33362?

The Meari IoT SDK used in versions of CloudEdge and Arenti products contains hardcoded security-critical secrets, including API signing materials and keying for password transport. This vulnerability arises from the improper storage of sensitive credentials within the software, potentially exposing these secrets to unauthorized access and exploitation. It affects a range of versions and could impact security across devices relying on this SDK, urging users to act promptly.

Affected Version(s)

com.meari.sdk firmID=8

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sammy Azdoufal
Tod Beardsley of runZero, Inc.
.