CVE-2026-33362 Details
Description
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.
A vulnerability exists in the Meari IoT SDK, which is embedded in CloudEdge version 5.5.0 (build 220), Arenti version 1.8.1 (build 220), and various white-label Android applications version 1.8.x or earlier. This vulnerability involves multiple security-sensitive secrets that are hardcoded and shared across these platforms, including API signing materials, keys for password encryption during transmission, and service access keys. The presence of these static keys in client binaries undermines the security of trust decisions reliant on them, allowing for unauthorized data access and the potential for replay attacks across different brands and tenants that utilize the same SDK and backend infrastructure.
There is no available remediation for this vulnerability, as the hardcoded keys cannot be rotated without re-flashing every device in the field.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/nobody-puts-baby-in-a-corner | runZero | BundleTechnical Analysis |
| https://www.runzero.com/advisories/meari-sdk-hardcoded-cryptographic-keys-cve-2026-33362/ | runZero | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | runZero |
Affected Products
| Product | Versions |
|---|---|
| Meari IoT SDK | All versions |
CPE
Remediation
| |
| Meari CloudEdge | All versions |
CPE
Remediation
| |
| Meari Arenti | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | runZero |
Volerion