Description
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized Information Disclosure
Action: Contact Vendor
AI Analysis

Impact

The vulnerability in Meari IoT Cloud Platform OpenAPI Service allows an authenticated user to retrieve the complete device shadow for any device by simply providing its device ID. The API does not verify whether the requester has an authorized relationship with the target device, exposing sensitive data such as device credentials, owner details, network information, and telemetry. Based on the description, it is inferred that this flaw can lead to privacy breaches, credential theft, and potential leverage of the exposed information for further attacks against the device or user network.

Affected Systems

The affected product is the Meari IoT Cloud Platform OpenAPI Service. No specific version or build information is provided, so all deployments of this service that are in use may be vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is not available, so the current estimated probability of exploitation cannot be quantified. It does not appear in the CISA KEV catalog. Based on the description, the attack vector is remote, requiring only authenticated access to the platform's API; an attacker who has valid credentials could exploit this flaw from any network location. Given the nature of the data exposed, this flaw poses a higher risk to affected devices and users than lower‑severity flaws, but the lack of a public exploit or documented evidence means the immediate threat is moderate pending vendor action.

Generated by OpenCVE AI on October 2, 2026 at 18:06 UTC.

Remediation

Vendor Workaround

Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter .


OpenCVE Recommended Actions

  • Contact Meari for support and any available patch or guidance.
  • Limit API access to trusted administrators only, disabling or protecting the endpoint for general users.
  • Implement network segmentation so that only internal segments can reach the OpenAPI service, or restrict access via firewall rules.

Generated by OpenCVE AI on October 2, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.
Title Missing Authorization in Meari IoT Cloud Platform OpenAPI Service
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-02T16:03:04.281Z

Reserved: 2026-09-29T16:11:36.326Z

Link: CVE-2026-96613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:52.490

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-96613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:15:13Z

Weaknesses