logo

Over 1 Million Baby Monitors, Security Cameras Exposed Through Meari Flaws

ID: ef2b5cdb-2223-5c7c-af8d-3855236efee8

STIX ID: report--ef2b5cdb-2223-5c7c-af8d-3855236efee8

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ken Underhill

...
...

Researchers disclosed that multiple vulnerabilities in Meari Technology’s camera/cloud ecosystem potentially exposed more than one million white‑label baby monitors and security cameras sold under 300+ brands, enabling unauthorized real‑time MQTT subscriptions (CVE-2026-33356), publicly accessible motion‑alert images on Alibaba OSS (CVE-2026-33359), and hardcoded/shared cryptographic keys and credentials (CVE-2026-33362); thousands of images were reportedly accessed and the incident highlights systemic IoT supply-chain and backend infrastructure risks and the need for patching, credential rotation, network segmentation, and vendor evaluation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.