A colleague of researcher Sammy Azdoufal recently bought a baby monitor on Amazon and, like any sensible person, asked if it was actually safe. It’s the kind of question we all ask ourselves before plugging in a new device, usually followed by a shrug and a hope that the brand name on the box knows what it’s doing. As it turns out, that hope is a multi-billion dollar liability.
At DEF CON 34, the curtain was pulled back on Meari Technology, a Hangzhou-based ODM that quietly powers the smart home industry. Meari doesn’t just make cameras; they build the entire stack—firmware, cloud backend, and mobile apps—and sell it to over 300 white-label brands. If you’ve bought a camera from Arenti, BOIFUN, COCOCAM, PetTec, SV3C, Joystek, Luvion, or Vimar, you are likely running Meari’s infrastructure. With 1.1 million registered devices across 118 countries, the scale of this operation is staggering.
The audit, presented as ‘1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud,’ revealed a series of high-severity vulnerabilities. The most alarming, CVE-2026-33356, highlights that the MQTT broker lacks per-device subscribe access control lists. In plain English: any authenticated CloudEdge account can subscribe to a ‘meari/#’ wildcard and watch every device on the platform in real time. During the research, 14,204 messages were captured from 2,117 distinct devices in just five minutes.
We are increasingly integrating these devices with AI agents like Alexa, Google Home, and Home Assistant, meaning these cameras are the eyes and ears of your AI. When the camera feed is compromised, your AI agent inherits that surveillance exposure. Trust breaks at the vision layer, turning your helpful assistant into an uninvited guest, a point explored in our recent look at the trust deficit.
The financial implications are as massive as the security failure. The global baby monitor market is worth $1.87 billion, with the U.S. accounting for roughly $540 million. Meari itself went public on the Shenzhen ChiNext board in March 2025, seeing its share price double in two days. Yet, retailers continue to sell products that are architecturally incapable of protecting user privacy. This is a different beast than the Zbtlink ENDLESSDOORS vulnerability, which targeted the infrastructure layer, but the structural thesis remains the same: we are buying convenience at the cost of total exposure.
Despite a 70-day disclosure window coordinated by Tod Beardsley of runZero, Meari’s initial response was to label the affected products as ‘obsolete.’ Meanwhile, the MQTT broker kept streaming. Per the researcher’s disclosure timeline on GitHub, there has been no confirmed GDPR Article 34 direct user notification, and users remain largely in the dark. This lack of accountability is exactly why many are turning toward local-first alternatives like Home Assistant, where privacy is treated as a competitive moat rather than an afterthought.
We have to stop assuming that a brand name on a box equates to security. The smart home trust model assumes the camera feed is private. Meari proves it is not.
