Meatmeet develops smart meat thermometer products with integrated Wi-Fi and Bluetooth connectivity, a niche consumer device category where vulnerabilities skew strongly toward critical-severity outcomes. The durable signal across its disclosures centers on authentication and data-protection shortcomings—missing authentication for critical functions, improper access control on debug interfaces, and cleartext storage and transmission of sensitive information—patterns typical of IoT devices where hardware interfaces and wireless protocols are often inadequately secured. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meatmeet over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65823CRITICAL The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the ph | Dec 10, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-65830CRITICAL Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt the TLS traffic, inspe | Dec 10, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-65827CRITICAL The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can inte | Dec 10, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-65820CRITICAL An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. This page, which | Dec 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-65826CRITICAL The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi netw | Dec 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-65824HIGH An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in t | Dec 10, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-65828MEDIUM An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Se | Dec 10, 2025 | 6.5 | 24 | NO | NO |
CVE-2025-65829MEDIUM The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can exe | Dec 10, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-65822MEDIUM The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical | Dec 10, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-65831HIGH The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS | Dec 10, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meatmeet.
Media articles that mention a CVE ID that affects a product developed by Meatmeet — matched by CVE ID, not by vendor name.