In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model. | |
| Title | Meari weak XOR obfuscation | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-05-11T18:17:43.933Z
Reserved: 2026-03-19T00:27:05.987Z
Link: CVE-2026-33361
No data.
Status : Received
Published: 2026-05-11T17:16:30.970
Modified: 2026-05-11T17:16:30.970
Link: CVE-2026-33361
No data.
OpenCVE Enrichment
Updated: 2026-05-11T18:00:14Z
Weaknesses