CVE-2026-101104High· 7.7▾ TwilightThe Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96613Medium· 6.5The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID
CVE-2025-12925High· 7.3A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2025-48614Medium· 4.6In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check
CVE-2025-48604Medium· 5.5In multiple locations, there is a possible way to read files from another user due to a missing permission check
CVE-2025-48599High· 7.8In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check
CVE-2025-48600Medium· 5.5In multiple files, there is a possible way to reveal information across users due to a missing permission check