CVE-2026-33357 Details
Description
In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is a server-side authorization failure in "GET /openapi/device/status".
A vulnerability exists in Meari client applications that use 'com.meari.sdk', including CloudEdge version 5.5.0 build 220 and Arenti version 1.8.1 build 220. These applications can access the 'openapi-euce.mearicloud.com' endpoint to retrieve WAN IP information for any device, exploiting a server-side authorization flaw in the 'GET /openapi/device/status' API. This issue enables geolocation of devices without user authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/nobody-puts-baby-in-a-corner | runZero | BundleTechnical Analysis |
| https://www.runzero.com/advisories/meari-openapi-device-status-idor-cve-2026-33357/ | runZero | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | runZero |
Affected Products
| Product | Versions |
|---|---|
| Meari IoT SDK | All versions |
CPE
Remediation
| |
| Meari CloudEdge | All versions |
CPE
Remediation
| |
| Meari Arenti | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | runZero |
Volerion