#CloudEdge
#Meari
#pet camera
#pet tech privacy
#smart pet feeder
The smart feeder or pet camera deal is risky if the app behind it depends on Meari’s CloudEdge platform and the seller gives you no clear security support path. A fresh CISA advisory says Meari’s IoT Cloud Platform OpenAPI Service has authorization flaws that could let authenticated users change device configurations or read sensitive device data. That does not mean every camera feeder has been hacked, but it does mean shoppers should check the app developer and return terms before treating a cheap camera feeder as a safe buy.
This matters now because camera feeders, treat cameras and budget indoor pet cams are often sold under different brand names while relying on shared cloud software. The box may talk about meal alerts, two-way audio or a pan-and-tilt bowl view, but the real question is who runs the cloud account that stores the device state, network details and owner information.
What changed with the Meari advisory
On October 1, 2026, CISA published advisory ICSA-26-274-06 for the Meari IoT Cloud Platform OpenAPI Service. CISA lists two missing-authorization vulnerabilities affecting all versions of that OpenAPI service. One is rated high and describes a path for authenticated users to manipulate configurations of devices they do not own. The other is rated medium and describes access to a device shadow, including credentials, owner details, network data and telemetry.
CISA also says it has not received reports of public exploitation specifically targeting these vulnerabilities at the time of the advisory. That detail matters. This is not a reason to panic-buy replacements, and it is not proof that a specific feeder in your kitchen has been accessed. It is a reason to stop treating “smart” pet devices as simple bowls with bonus video.

The checkout question most listings do not answer
Before you buy a camera feeder or budget pet cam, check the app store listing for the app named in the product manual. The brand printed on the feeder is not always the company running the account system. If the app developer is Hangzhou MEARI Technology Co., Ltd., Meari, CloudEdge or a closely related white-label app, this advisory is relevant to your risk check.
If the listing does not name the app clearly, treat that as a shopping problem. A pet-tech deal should tell you which app controls schedules, video, account sharing, cloud storage and firmware updates. If you need to buy first to discover the app, the return window becomes part of the real price.
What to verify before paying
- App developer: read the developer name in the Apple App Store or Google Play listing, not just the product brand on the retail page.
- Update history: check whether the app has recent updates and useful release notes. Vague “bug fixes” notes are common, but a long-abandoned app is a bigger red flag.
- Manual controls: confirm whether feeding schedules can run locally on the device if the app or cloud service is unavailable.
- Camera placement: buy only if you can point the camera at the bowl, not across a private room.
- Account sharing: check how sitter access works and whether you can remove shared users quickly.
- Returns and warranty: save the listing, support page and return policy before setup. Security uncertainty is harder to argue after the return window closes.
When a deal is not really a deal
A cheap camera feeder can still be a good buy if you understand the tradeoff. It is less attractive when the seller hides the app name, bundles video features behind a subscription, or gives no clear answer about who maintains the cloud service. The discount is also weaker if you need a backup feeder, a separate pet camera, or a guest Wi-Fi network upgrade to feel comfortable using it.
Do not compare only hopper size and camera resolution. Compare the total ownership cost: cloud clips, replacement power adapters, return shipping, warranty length, support responsiveness and whether the feeder still dispenses meals when remote features fail.
What current owners should check
If you already use a CloudEdge or Meari-connected pet device, start with low-risk housekeeping. Put the device on a guest Wi-Fi network if your router supports one. Aim the camera only at the food bowl or litter area you intentionally monitor. Review feeding schedules, shared users and app permissions. If a setting changes without you making the change, unplug the device and contact the seller or manufacturer.
Changing your home Wi-Fi password can help if you think an account or device was mishandled, but it is not a complete answer to a cloud-side authorization flaw. The key shopper lesson is simpler: a camera feeder is partly a cloud service, so the company behind that service matters as much as the plastic bowl.

What to avoid
Avoid marketplace listings that show no app name, no manufacturer support page and no clear warranty contact. Avoid used smart feeders unless the seller can prove the old account has been removed. Avoid pointing any pet camera at bedrooms, desks, documents, security keypads or doors where visitors appear. Avoid relying on an app-controlled feeder as the only feeding plan for a pet that cannot safely miss a meal.
Also avoid assuming a famous retail platform has checked the software behind every third-party listing. Retail return policies can help after a bad purchase, but they do not turn an unknown cloud platform into a well-supported one.
Quick answers
Should I throw away a CloudEdge pet camera or feeder?
Not automatically. Check the app developer, limit camera placement, review account sharing and decide whether you are comfortable using the device while Meari support or CISA guidance remains the best source for updates.
Is this only about dog and cat feeders?
No. CISA’s advisory is about Meari’s IoT Cloud Platform OpenAPI Service. Pet shoppers care because camera feeders and budget pet cams can depend on the same kind of cloud platform, even when sold under different consumer brands.
Can a coupon make this risk worth it?
Only if the product still passes the support, privacy and return checks. A discount does not help much if the device becomes uncomfortable to keep connected after the return window ends.
What is the safest alternative?
For feeding, a non-camera automatic feeder with reliable local scheduling may be enough. For monitoring, a separate camera from a company with clear security updates can be easier to evaluate than a combined feeder-camera deal.
Sources
Sources last checked: October 3, 2026, 07:32 Europe/Rome.
- CISA CSAF advisory ICSA-26-274-06, Meari IoT Cloud Platform OpenAPI Service
- CISA web advisory page for ICSA-26-274-06
- Meari Security Center
- runZero advisory on Meari SDK hardcoded cryptographic keys
- GitHub Advisory Database, GHSA-w7mj-frmj-5g6g
- PetTechScout coverage connecting the Meari advisory to camera pet feeders
- FTC guidance on securing a home Wi-Fi network