Impact
The vulnerability in the Meari IoT Cloud Platform OpenAPI Service allows an authenticated attacker to modify the configuration of devices that they do not own. By issuing API calls while logged in, a user can alter device settings or trigger unintended behaviours without any additional verification of ownership or permission, potentially causing unexpected or harmful device behaviour.
Affected Systems
All installations of the Meari IoT Cloud Platform OpenAPI Service are impacted; the specific affected firmware or software release is not disclosed in the public data. Any Meari IoT device that relies on this OpenAPI Service for configuration management or control is a potential target for the flaw.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity vulnerability. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalogue. The vulnerability requires the attacker to possess valid user credentials, indicating that the attack vector is inferred to be authenticated and likely internal or delegated. Because of the lack of publicly known exploitation methods, the exploitation probability remains uncertain, but the potential impact on device behaviour and possible downstream effects makes it a relevant risk for organisations managing a fleet of Meari devices.
OpenCVE Enrichment