Impact
The vulnerability in Meari IoT Cloud Platform OpenAPI Service allows an authenticated user to retrieve the complete device shadow for any device by simply providing its device ID. The API does not verify whether the requester has an authorized relationship with the target device, exposing sensitive data such as device credentials, owner details, network information, and telemetry. Based on the description, it is inferred that this flaw can lead to privacy breaches, credential theft, and potential leverage of the exposed information for further attacks against the device or user network.
Affected Systems
The affected product is the Meari IoT Cloud Platform OpenAPI Service. No specific version or build information is provided, so all deployments of this service that are in use may be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is not available, so the current estimated probability of exploitation cannot be quantified. It does not appear in the CISA KEV catalog. Based on the description, the attack vector is remote, requiring only authenticated access to the platform's API; an attacker who has valid credentials could exploit this flaw from any network location. Given the nature of the data exposed, this flaw poses a higher risk to affected devices and users than lower‑severity flaws, but the lack of a public exploit or documented evidence means the immediate threat is moderate pending vendor action.
OpenCVE Enrichment