Vulnerability Description
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/xn0tsa/nobody-puts-baby-in-a-corner
- https://www.runzero.com/advisories/meari-sdk-hardcoded-cryptographic-keys-cve-20
FAQ
What is CVE-2026-33362?
CVE-2026-33362 is a vulnerability with a CVSS score of 8.6 (HIGH). In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and...
How severe is CVE-2026-33362?
CVE-2026-33362 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33362?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.