CVE-2026-33361Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-326

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-11: 3Technical Details · 2026-05-11: 205-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Sammy Azdoufal@n0tsa
    Disclosure

    6/ CVE-2026-33361 (CVSS 7.5) : Baby-monitor images are "encrypted" with XOR. Alert images on baby-monitor SKUs use a .jpgx3 extension. It's a JPEG with the first 1024 bytes XOR'd against MD5(serial | len(serial) | secret). The serial is in the same MQTT message.

    Post summary

    The entry discloses that images from certain baby‑monitor SKUs are XOR‑encrypted using a serial‑based MD5 hash, making the CVE‑2026‑33361 a potential vulnerability with a CVSS score of 7.5.

    100401.1K
    11.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33361 In Meari IoT SDK image handling (http://libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (&lt;= 1.8.x), baby m… https://www.cve.org/CVERecord?id=CVE-2026-33361

    Post summary

    The tweet merely references CVE‑2026‑33361, citing affected Meari IoT SDK builds, but provides no PoC, exploit, patch, or technical details.

    00000140
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-33361 In Meari IoT SDK image handling (http://libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), … CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-33361 #IBM #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2026‑33361, a high severity flaw in Meari IoT SDK image handling, and directs readers to a detailed analysis.

    0000051
    90 followersView on X

Explore more