A major security review at DEF CON 34 reveals significant vulnerabilities in Meari Technology’s cloud-based platform, risking the privacy of millions of connected cameras and baby monitors globally and raising questions about accountability in the white-label IoT market.
A major security review unveiled at DEF CON 34 has exposed a deep flaw in the architecture behind a large slice of the smart camera market, raising fresh doubts about the privacy claims attached to white-label internet-connected devices. The finding centres on Meari Technology, a Hangzhou-based original design manufacturer that supplies the full stack for cameras and baby monitors, including firmware, cloud services and mobile apps, to hundreds of brands sold across more than 100 countries.
According to reporting from TechRepublic and The Brief, the issue is not limited to a single faulty product but to a platform design that allowed broad visibility across devices. Researchers said the MQTT broker used by the system did not enforce per-device access controls, meaning an authenticated CloudEdge user could subscribe to a wildcard feed and view traffic from other devices. In the course of testing, investigators captured thousands of messages from more than 2,000 devices in just minutes.
The technical implications are severe because these systems are designed to carry live video, audio alerts and other household data. SentinelOne has separately documented another Meari flaw, CVE-2026-33361, involving weak XOR encryption in the company’s IoT SDK, underscoring that the exposure was not a one-off mistake but part of a wider pattern of weak protection around sensitive camera data. Security researchers and commentators have warned that such weaknesses can expose images, device identifiers and real-time activity inside homes.
The scale of the commercial footprint makes the problem more significant. Forkast reported that the global baby monitor market is worth $1.87 billion, with the US accounting for roughly $540 million. It also noted that Meari listed on Shenzhen’s ChiNext board in March 2025 and saw its share price double within two days, despite the company’s products sitting inside a sprawling white-label ecosystem that can make accountability difficult when vulnerabilities emerge.
Meari’s security centre says it operates a vulnerability handling process and has previously published advisories for other issues, including Apache Log4j2-related flaws and problems in the EMQX component. But the recent disclosure has sharpened criticism of how quickly manufacturers, distributors and retailers can distance themselves from responsibility when a defect affects a common cloud platform rather than a single branded camera. The research timeline, as described by the investigators, suggests users may still have limited direct notice despite the breadth of the exposure.
For consumers, the lesson is straightforward. A trusted brand on the box does not necessarily mean the device is isolated, private or safe. In a market built on convenience, the risk is that the camera in the nursery is not only watching the room but, if the underlying cloud design is weak, could be part of a much larger stream seen by others.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





