Description
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
Product status
firmID=8 (custom)
Credits
Sammy Azdoufal
Tod Beardsley of runZero, Inc.
References
github.com/xn0tsa/nobody-puts-baby-in-a-corner
www.runzero.com/...dcoded-cryptographic-keys-cve-2026-33362/