More than 1.1 million Wi-Fi baby monitors and security cameras made by Meari Technology were susceptible to a flaw that let outsiders reach live video, stored photos, email addresses and location data. Consumer Reports says a single number in a device’s settings shows whether a monitor has the fix: firmware version 3.0.0 or higher.
The check takes a minute, but it is easy to overlook because the affected monitors are sold under names that never mention Meari. A parent looking at a box that says Arenti or Boifun would have no reason to connect it to a manufacturer in the news, which is why the brand list and the firmware number are the useful details.
Exposed feeds and the researchers who found them
Security researcher Sammy Azdoufal disclosed five vulnerabilities in Meari’s CloudEdge camera platform on May 11, 2026, according to his public GitHub write-up. The timeline in that document runs from initial discovery on March 2 to a first vendor response on March 11, a signed disclosure agreement on April 28 and public release on May 11. The write-up estimates 1.1 million devices in more than 118 countries.
The most serious flaw, CVE-2026-33362, carried a severity score of 8.6 and involved hardcoded cryptographic keys in the client software shared across the ecosystem. Another, CVE-2026-33356, scored 7.7 and is described in the National Vulnerability Database as an authorization bypass in the Meari cloud’s message broker: low-privilege users could subscribe to topics and read telemetry from devices they did not own, because the system restricted publishing but not subscribing.
Practically, eSecurityPlanet’s summary of the research says any free CloudEdge account could allegedly subscribe to device notifications across the platform. Motion-alert images were kept in cloud storage with no authentication or expiry, and an exposed endpoint revealed device WAN IP addresses, which can indicate roughly where a household is located.
The brands and the number to look for
Consumer Reports names the affected brands as Arenti, Anran, Boifun and ieGeek, along with Petcube’s pet camera line. A separate analysis counts more than 300 white-label brands selling the same hardware and firmware from one Meari cloud backend, and advises identifying the pairing app rather than the label on the box. If that app is CloudEdge, the device likely runs on the affected platform.
In its report on the issue, Consumer Reports tells owners to look under a monitor’s Settings or About menu and confirm it runs firmware 3.0.0 or higher. Below that number, the report indicates, the problem is not resolved. The report also says it is unclear whether all devices will be able to be updated, and that no recall or safety warning had been issued when it was published on May 20.
Meari’s public response was brief. In a statement quoted by Consumer Reports, the company said it was “currently conducting internal verification regarding relevant reports.” The researcher’s write-up, for its part, records that Meari described some affected products as obsolete while the message broker kept running during the disclosure window, and that no user notifications had been confirmed.
Consumer Reports gives the location of the number as the monitor’s Settings or About menu, and the test as 3.0.0 or higher. A reading below that means the monitor falls short of the fix the magazine describes, and the pairing app is the place to look for an update. Because the affected products share one cloud backend and one firmware line under many labels, the number matters more than the brand printed on the box, and it applies the same way to a pet camera as to a nursery monitor.
What owners can do if the number is too low
The secureiot.house analysis raises a harder problem: budget cameras sold years ago through marketplace sellers may never receive a firmware update at all. A monitor stuck below 3.0.0 with no update option is the case in which a fix on the manufacturer’s side does not reach the household.
Stacey Higginbotham of Consumer Reports put the wider issue this way: “Unfortunately for consumers, companies selling connected devices in the U.S. don’t have to follow any mandatory baseline security requirements.” Her recommended steps were to put a Wi-Fi baby monitor on a separate guest network, keep firmware current, and choose devices that offer multifactor authentication and require complex passwords. Consumer Reports suggests passwords of at least 16 characters and monthly firmware checks.
The unanswered question is how many of the 1.1 million devices can actually be brought to 3.0.0. Neither the researcher’s timeline nor the Consumer Reports article gives a count of updated units, and that figure would show how much of the exposure has really closed.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- General Motors is switching on cameras that record inside your vehicle by update
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south
- A recalled pill hid a stimulant dose linked to heart attacks and death