Description
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorised configuration changes to IoT devices via the OpenAPI service
Action: Assess Impact
AI Analysis

Impact

The vulnerability in the Meari IoT Cloud Platform OpenAPI Service allows an authenticated attacker to modify the configuration of devices that they do not own. By issuing API calls while logged in, a user can alter device settings or trigger unintended behaviours without any additional verification of ownership or permission, potentially causing unexpected or harmful device behaviour.

Affected Systems

All installations of the Meari IoT Cloud Platform OpenAPI Service are impacted; the specific affected firmware or software release is not disclosed in the public data. Any Meari IoT device that relies on this OpenAPI Service for configuration management or control is a potential target for the flaw.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity vulnerability. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalogue. The vulnerability requires the attacker to possess valid user credentials, indicating that the attack vector is inferred to be authenticated and likely internal or delegated. Because of the lack of publicly known exploitation methods, the exploitation probability remains uncertain, but the potential impact on device behaviour and possible downstream effects makes it a relevant risk for organisations managing a fleet of Meari devices.

Generated by OpenCVE AI on October 2, 2026 at 17:30 UTC.

Remediation

Vendor Workaround

Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter .


OpenCVE Recommended Actions

  • Contact Meari for support and request a fix or mitigation guidance
  • Restrict or disable the OpenAPI service for devices until a vendor-approved solution is available
  • Implement network segmentation or firewall rules to allow OpenAPI traffic only from trusted management IPs
  • Enable detailed logging and auditing of OpenAPI requests to detect any policy violations
  • Apply role‑based access controls ensuring that authenticated users can only alter configurations for devices they own

Generated by OpenCVE AI on October 2, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
Title Missing Authorization in Meari IoT Cloud Platform OpenAPI Service
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-02T15:58:21.626Z

Reserved: 2026-09-29T16:11:36.322Z

Link: CVE-2026-101104

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:42.883

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-101104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses