Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
Vendor
Equipment
Meari
Meari IoT Cloud Platform OpenAPI Service
Missing Authorization
Critical Infrastructure Sectors: Commercial Facilities, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform...