The Meari Cloud Vulnerability Reaches Camera Pet Feeders, and No Fix Is Planned

The Meari Cloud Vulnerability Reaches Camera Pet Feeders, and No Fix Is Planned

If you set up a camera pet feeder or a budget pet cam through the CloudEdge app, the company behind that app runs a cloud service with two open authorization flaws. On October 1, 2026 the US Cybersecurity and Infrastructure Security Agency (CISA) published them in advisory ICSA-26-274-06. An account on Meari’s OpenAPI service can change settings on devices it does not own and read another device’s stored data, owner details included. Meari did not answer CISA, and both flaws are listed with no fix planned.

What the two flaws allow

CISA’s advisory covers every version of the Meari IoT Cloud Platform OpenAPI Service, the server side that apps and partner software talk to. Both flaws are the same kind of mistake: the service checks that you are logged in but not that the device you name is yours.

The more serious one, CVE-2026-101104, is rated 7.7 out of 10. It lets anyone who is logged in change the configuration of someone else’s device, which CISA describes as “altering device settings or triggering unintended behaviors”. On a feeder, settings include the feeding schedule, though the advisory does not say what an attacker could change on any particular product.

The second, CVE-2026-96613, is rated 6.5. It lets a logged-in account read the complete “device shadow” of any device by giving its ID. A device shadow is the cloud’s stored copy of a device’s state and settings, and CISA lists what it exposes: device credentials, owner details, network data and telemetry.

CISA says nobody has reported exploiting either flaw so far.

The account question the advisory leaves open

Both flaws need someone to be logged in first. CISA does not say whether that means anyone with a free CloudEdge login or only a business with a developer account on Meari’s OpenAPI service. If it is the first, the flaws are within reach of anyone who downloads the app. A developer account would narrow them to Meari’s partners and anyone who gets hold of a partner’s keys.

The device ID is the other unknown. An attacker needs one to aim at a specific feeder, and CISA has not said how IDs are issued or whether they can be guessed.

Until Meari or CISA answers those two points, the fair reading is that the risk is real but not yet sized.

Why there is nothing to update at home

Our September advisory piece on CareCam cameras covered flaws in a camera’s own firmware, reachable from your home network. This is the opposite case. The weak check sits on Meari’s servers, so every feeder and camera that talks to that platform shares it, and only Meari can close it.

Meari could fix it quietly, with no firmware release and no note to owners. CloudEdge version 6.3.5 reached the App Store on October 2 with the release note “fix some bugs”, and nothing links it to this advisory.

The silence is odd for a company with a security team. Meari’s own security center names a product security response team as the channel for vulnerability reports, and it has published advisories before, including a CloudEdge information disclosure issue on March 12, 2026. Nothing about these two flaws appears there.

CISA’s standard advice is written for industrial networks: firewalls, isolation from business systems, VPNs. A feeder that needs the maker’s cloud to send you a photo of the bowl cannot follow most of it.

Diagram showing a camera pet feeder sending its settings to a cloud device shadow, with a missing ownership check letting a second account read and change it

Whose cloud runs your feeder

The brand on the box is often not the company running the cloud. Meari makes cameras and feeders for other brands, and its catalog includes its own PET 3 feeder with a 3 MP camera, a 0.5 L hopper and a camera that pans 355 degrees.

The reliable check is the developer name on the app’s store listing. CloudEdge is published by Hangzhou MEARI Technology Co.,Ltd., and Meari also publishes an app under its own name. If your feeder’s app lists either of those, this advisory is about your account.

If it lists someone else, it is not. The PetKit YumShare Solo 2, for example, is set up in the PETKIT app, published by Petkit Smart Technology Limited. That says nothing about how secure PETKIT’s own cloud is. It only means a different company answers for it.

What to do this week

  1. Open the app store page of the app that runs your feeder or pet cam and read the developer line.
  2. If it is Meari, move the feeder onto your router’s guest network, so any network details stored in its shadow do not lead into the network your laptop and phone use.
  3. Point the camera at the bowl rather than at a sofa or a bedroom door. If someone else reads the shadow, the view is the part you cannot take back.
  4. Check the feeding schedule and the list of people the feeder is shared with once a week, and treat any change you did not make as a reason to unplug the feeder.
  5. Write to Meari through the contact on its download center, which is where CISA sends owners, and ask whether the fix has been made on the server.

If Meari confirms a server-side fix or CISA revises the advisory, the guest network can stay and the weekly check can stop. If nothing changes by the time you next replace the feeder, buy from a maker that publishes its own security contact and answers when a government agency writes to it.

Basis
Research-based: written from the manufacturer’s published information and other public sources. We have not used the products discussed ourselves, and any measurement quoted belongs to its source.

← Back to the blog