Severe vulnerabilities in Meari Technology’s white-label IoT platform exposed more than 1 million baby monitors and security cameras across 118 countries, affecting devices sold under hundreds of brands on marketplaces including Amazon. Researcher Sammy Azdoufal reported that weaknesses in Meari’s hardware, mobile apps, SDKs, cloud services, and backend infrastructure allowed unauthorized access to MQTT message streams, device data, user email addresses, rough location information, WAN IP addresses, and real-time camera activity. Publicly accessible motion-alert images stored on Alibaba OSS and missing per-device access controls on Meari’s EMQX-based IoT platform left sensitive household photos and notifications exposed, raising particular concern for devices deployed in bedrooms, nurseries, and other private spaces.
Meari acknowledged that attackers could intercept messages without authorization and disclosed a potential remote code execution risk linked to weak passwords on a scheduled task platform. The company said it shut down the exposed EMQX platform, changed credentials, and advised firmware upgrades for devices running versions below 3.0.0, while Azdoufal said five CVEs were coordinated with runZero and CISA under VU#579666. A published disclosure timeline alleges Meari delayed responding, minimized some findings, used backdated advisories that covered only part of the issues, and failed to directly notify affected EU users or confirm GDPR breach reporting; Azdoufal later received a €24,000 bug bounty after an agreement preserved his right to publish the findings.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
After the disclosure, Azdoufal received a €24,000 bug bounty and filed five CVE reports related to the Meari vulnerabilities with support from runZero.
Subsequent reporting said the flaws affected more than 300 white-label brands sold through marketplaces such as Amazon, highlighting supply-chain risk in Meari's hardware, apps, SDKs, and cloud infrastructure.
On May 11, reporting and the research disclosure revealed that vulnerabilities in Meari's white-label ecosystem exposed roughly 1.1 million baby monitors and security cameras across 118 countries, including access to device data, MQTT streams, user details, and publicly reachable images.
Meari said it shut down the vulnerable EMQX IoT platform, changed credentials, and advised firmware upgrades for devices running versions below 3.0.0 in response to the reported flaws.
Azdoufal published a detailed disclosure timeline documenting the responsible disclosure process, unresolved architectural issues, and allegations that Meari did not directly notify affected EU users or confirm GDPR notifications to regulators.
On April 28, Azdoufal and Meari signed a final agreement allowing unrestricted publication on May 11 and removing proposed restrictive terms such as refund, long-term NDA, and non-disparagement clauses.
Five vulnerabilities remained in scope after retesting, and Azdoufal coordinated disclosure with Tod Beardsley of runZero and CISA VINCE case VU#579666.
According to the disclosure timeline, Meari initially described affected products as obsolete, minimized some findings, and published advisories that allegedly backdated fixes to March 2 while covering only part of the reported issues.
After Azdoufal reported the issues by email and LinkedIn, Meari did not respond for nine days despite repeated outreach, delaying the responsible disclosure process.
During the early audit, Azdoufal found exposed services including an EMQX dashboard with default credentials and a publicly accessible Apollo configuration server, along with broader weaknesses across Meari's platform.
Sammy Azdoufal began auditing Meari Technology's CloudEdge IoT ecosystem and related backend infrastructure, starting the investigation that uncovered multiple severe security issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcetheverge.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.