External risk intelligence

Meatmeet Pro Firmware Hardcoded Wi-Fi Credentials Allow Network Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-65823

The vulnerability involves hardcoded credentials for a local Wi-Fi network and requires the attacker to be in close physical proximity to the device during initial setup to force a connection. It is not an internet-facing service or remote network-accessible component.

Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware

1.0.34.4

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in Meatmeet Pro devices where hardcoded Wi-Fi credentials for a development network were discovered within the firmware. If an attacker obtains these credentials and can locate the original test network, they could gain unauthorized access to the vendor's Wi-Fi. Additionally, proximity during device setup could allow an attacker to redirect the device to their own network.

  • Hardcoded Wi-Fi passwords found in device firmware.
  • Confirms potential unauthorized vendor network access.
  • Assess relevance and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An attacker could discover hardcoded Wi-Fi credentials within the device's firmware, potentially gaining unauthorized access to the vendor's test network. If in close physical proximity during setup, the attacker might trick the device into connecting to a malicious access point using the compromised credentials. This could lead to significant data breaches, system compromise, or unauthorized control.

  • Requires physical proximity or firmware access.
  • Triggers by connecting to a crafted Wi-Fi.
  • Risk: Unauthorized network access and control.

Live Threat

Current exploitation, exposure, and threat context

The Meatmeet Pro firmware contains hardcoded Wi-Fi credentials from its development environment. An attacker in physical proximity could potentially leverage these credentials to gain unauthorized access to the vendor's Wi-Fi network or trick the device into connecting to a rogue access point during initial setup.

  • Vendor Wi-Fi network credentials.
  • Physical proximity and device setup.
  • Unauthorized network access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Meatmeet Pro firmware contains hardcoded Wi-Fi credentials, posing a risk if an attacker can access the test network or trick the device into connecting to a malicious access point during setup. Identifying the deployment locations of this device, confirming its reachability and business criticality, and then assigning ownership for remediation planning is the crucial first step.

  • Issue ownership by firmware or device management team.
  • Verify device deployment and network exposure.
  • Plan firmware update or network segmentation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Meatmeet Pro device?

The Meatmeet Pro is a smart meat thermometer featuring both Wi-Fi and Bluetooth connectivity, designed to help users monitor cooking temperatures remotely via a wireless network.

What does CWE-798 mean for CVE-2025-65823?

CWE-798 refers to the use of hardcoded credentials. In this case, the device firmware contains a pre-set Wi-Fi username and password intended for the manufacturer's internal testing. Because these credentials are embedded in the code, they cannot be changed by the user, creating a permanent security weakness that attackers could potentially discover.

How can an attacker trigger this vulnerability?

An attacker must be in close physical proximity to the thermometer during its initial setup to force the device to connect to a rogue, attacker-controlled wireless network. Simply using the device in a normal home environment does not trigger the bug unless the attacker creates a network that matches the specific hardcoded credentials found in the firmware.

Is my device vulnerable according to Halo Surface Signal?

Halo Surface Signal indicates that this vulnerability is very unlikely to be exploited remotely. Because the issue requires physical proximity during the initial setup process and is not an internet-facing service, it does not pose a standard remote network-accessible risk.

What should I do if I use Meatmeet Pro?

You should begin by verifying where these devices are deployed and who manages them within your environment. Consult the manufacturer for available firmware updates that remove these credentials, and consider isolating these thermometers on a separate, restricted network to limit potential impact.

References