Description
In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.
Problem types
CWE-326 Inadequate Encryption Strength
Product status
firmID=8 (custom)
Credits
Sammy Azdoufal
Tod Beardsley of runZero, Inc.
References
github.com/xn0tsa/nobody-puts-baby-in-a-corner
www.runzero.com/...eari-weak-xor-obfuscation-cve-2026-33361/