Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-33357

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published May 11, 2026
Vendor unknown

Description

In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is a server-side authorization failure in "GET /openapi/device/status".

References