
4/ CVE-2026-33357 (CVSS 7.5) : Device-status IDOR. GET /openapi/device/status returns the WAN IP of any camera by serial number. No user authentication. The signing key is hardcoded in every Meari-based app shipped to the public.
Post summary
The tweet discloses CVE‑2026‑33357, an IDOR that exposes a camera’s WAN IP without authentication.

