Sammy Azdoufal
15 exploits
Active since May 2026
Aqara Developer Portal insecure authentication token
CVSS 6.5
Aqara hardcoded OAuth client credentials
CVSS 9.1
Aqara API cross-account access
CVSS 9.6
Aqara Board IoT insecure debug API
CVSS 8.6
Aqara unauthenticated AES oracle
CVSS 10.0
Aqara IAM/SSO Gateway cross-origin resource sharing
CVSS 8.2
Aqara Developer Portal cross-origin resource sharing
CVSS 8.2
Aqara IAM/SSO Gateway open redirect
CVSS 6.1
Aqara OAuth redirect_uri validation bypass
CVSS 9.3
Aqara Home Android SDK hardcoded keys
CVSS 9.1
Meari MQTT broker missing per-device subscribe ACL
CVSS 7.7
Meari OpenAPI device status IDOR
CVSS 7.5
Meari unauthenticated alert image access in cloud object storage
CVSS 7.5
Meari weak XOR obfuscation
CVSS 7.5
Meari SDK hardcoded cryptographic keys
CVSS 8.6