
7/ CVE-2026-33362 (CVSS 8.6) : Static keys across the whole ecosystem. Every Meari-based app ships the same HMAC secret, the same DES key for passwords, the same OpenAPI key, the same P2P password. None can rotate without re-flashing every device in the field.
Post summary
The tweet discloses CVE‑2026‑33362, highlighting that all Meari-based apps ship identical keys, a configuration flaw with a CVSS score of 8.6.

