Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Meari SDK hardcoded cryptographic keys
Vulnerability Description
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
Meari IoT SDK 安全漏洞
Vulnerability Description
Meari IoT SDK是中国觅睿(Meari)公司的一个面向智能设备应用开发的物联网通信与设备管理软件开发工具包。 Meari IoT SDK存在安全漏洞,该漏洞源于多个安全关键密钥被硬编码并共享,包括API签名材料、密码传输密钥和服务访问密钥。
CVSS Information
N/A
Vulnerability Type
N/A