CVE-2026-33361

In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.
Configurations

No configuration.

History

11 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 17:16

Updated : 2026-05-13 15:36


NVD link : CVE-2026-33361

Mitre link : CVE-2026-33361

CVE.ORG link : CVE-2026-33361


JSON object : View

Products Affected

No product.

CWE
CWE-326

Inadequate Encryption Strength