CISA

Meari IoT Cloud Platform OpenAPI Service

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.

The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:

IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)

Vendor

Equipment

Meari

Meari IoT Cloud Platform OpenAPI Service

Missing Authorization

Critical Infrastructure Sectors: Commercial Facilities, Information Technology

Countries/Areas Deployed: Worldwide

Company Headquarters Location: China

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform...