CVE-2026-33361 Details
Description
In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.
A vulnerability exists in the Meari IoT SDK's image processing within the library libmrplayer.so, as seen in CloudEdge version 5.5.0 (build 220), Arenti version 1.8.1 (build 220), and other related white-label applications version 1.8.x or earlier. The issue arises with baby monitor alert images saved as '.jpgx3' files, which are obfuscated using a reversible XOR operation applied only to the first 1024 bytes. This obfuscation employs a predictable key derived from the image's serial number, allowing for easy decryption and access to the original image content.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/nobody-puts-baby-in-a-corner | runZero | BundleTechnical Analysis |
| https://www.runzero.com/advisories/meari-weak-xor-obfuscation-cve-2026-33361/ | runZero | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | runZero |
Affected Products
| Product | Versions |
|---|---|
| Meari IoT SDK | All versions |
CPE
Remediation
| |
| Meari CloudEdge | All versions |
CPE
Remediation
| |
| Arenti | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | runZero |
Volerion