Meari IoT 云平台 OpenAPI 服务存在一处授权缺陷,导致经过身份验证的用户可以通过指定设备 ID,访问任意设备的完整设备影子(device shadow)数据。该漏洞在未验证请求者与目标设备之间是否存在任何关联关系的情况下,泄露了敏感信息,包括设备凭据、所有者详情、网络数据和遥测数据等。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Meari | IoT Cloud Platform OpenAPI Service | All verisons |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Meari | IoT Cloud Platform OpenAPI Service | All verisons | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet