Meari IoT Cloud Platform OpenAPI Service
What happened
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI Service Vendor: Meari Product Version: Meari IoT Cloud Platform OpenAPI Service: vers:all/* Product Status: known_affected Remediations No fix planned Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter . Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Sources & evidence
- CISA Advisories Primary / official
Meari IoT Cloud Platform OpenAPI Service ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06