Meross manufactures a focused line of smart home networking and power-management devices, including its MSH and MSG product families, where vulnerabilities skew strongly toward critical severity. The recurring weakness pattern centers on authentication and credential handling—capture-replay attacks, cleartext transmission of sensitive data, hard-coded credentials, and improper authentication mechanisms—reflecting the security challenges of embedded IoT devices with minimal local processing or secure storage. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meross over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6401CRITICAL Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password. | May 2, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-10544CRITICAL Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface. | May 2, 2018 | 9.8 | 28 | NO | NO |
CVE-2023-46892HIGH The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communica | Jan 23, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-35067HIGH Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message). | Oct 7, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-3774MEDIUM Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. Thi | Nov 5, 2021 | 6.5 | 22 | NO | NO |
CVE-2023-46889MEDIUM Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this | Jan 23, 2024 | 5.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meross.
Media articles that mention a CVE ID that affects a product developed by Meross — matched by CVE ID, not by vendor name.