[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-meari-iot-cloud-bugs-expose-any-devices-data-and-controls":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},9391,"meari-iot-cloud-bugs-expose-any-devices-data-and-controls","Meari IoT Cloud Bugs Expose Any Device's Data and Controls","Two unpatched bugs in Meari's IoT cloud API let any logged-in user view or alter devices they don't own, and the vendor has no fix planned.","Meari's cloud backend for its internet-connected cameras and smart devices has two authorization holes that let any logged-in user peek at or tamper with gear that isn't theirs, and the vendor has no plans to fix it.\n\nThe flaws sit in the Meari IoT Cloud Platform OpenAPI Service, the backend that lets apps and integrators talk to Meari hardware. CVE-2026-101104 lets an authenticated user change the configuration of devices they do not own, with no check that they actually have permission, a bug rated 7.7 on the CVSS 3.1 scale. CVE-2026-96613 is worse in practice: anyone who knows a device's ID can pull its entire device shadow, including credentials, owner details, network data, and telemetry, without proving any relationship to that device. Both trace back to the same root cause, a missing-authorization flaw classified as CWE-862, and affect every version of the service. There is no patch and none is planned; the vendor, based in China, did not respond when the government tried to coordinate a fix.\n\nThat matters because this isn't a one-off camera bug, it's the authorization layer for a cloud service deployed worldwide across commercial and consumer hardware. Any device tied to this API is only as private as its ID number, which is not a secret. Security researcher Gabriel Adams gets credit for finding it, and there is no sign yet that anyone is exploiting it in the wild.\n\nThe advised fix is the usual one for abandoned IoT backends: keep the device off the open internet and hope the cloud API never gets found. For a service whose entire job is to be reachable from the internet, that is not really a fix at all.","[\"iot\",\"vulnerability\",\"meari\",\"authorization\"]","2026-10-01T12:00:00.000Z","2026-10-02T15:29:19.325Z","2026-10-02T15:29:25.644Z","published",null,[],"security",[26,27,28,29],"iot","vulnerability","meari","authorization",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-274-06",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",5721,"2026-10-01T19:45:44.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",829,"2026-10-01T17:31:56.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",437,"2026-10-01T18:10:00.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",317,"2026-10-01T22:00:00.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",198,"2026-10-01T17:38:48.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",168,"2026-10-01T18:35:55.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",155,"2026-10-01T19:54:10.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Dev Tools","dev-tools",96,"2026-10-01T16:57:03.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",93,"2026-09-30T21:41:11.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",90,"2026-10-01T21:55:22.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",50,"2026-09-30T21:37:54.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]