Meatmeet Pro Hardcoded Wi-Fi Credentials Vulnerability

Vulnerability

A vulnerability exists in the Meatmeet Pro BBQ Thermometer in version 1.0.34.4, where hardcoded Wi-Fi credentials for the vendor's test network are embedded in the firmware. This flaw allows an attacker who extracts the credentials and identifies the physical location of the corresponding Wi-Fi network to gain unauthorized access. Furthermore, if the attacker is in close proximity to the device during its initial setup, they could potentially manipulate the device to connect automatically to an access point they control, by matching the SSID and password to those found in the firmware.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the vendor's Wi-Fi network. Additionally, if the device is forced to connect to an attacker-controlled access point, it could allow for further interception or manipulation of data.

Reproduction

The vulnerability can be reproduced by disassembling the Meatmeet Pro BBQ Thermometer to access the internal circuit board. Once the device is opened, connect to it using probes and a USB-UART adapter over UART. After putting the device into download mode, the firmware can be dumped and analyzed. The hardcoded Wi-Fi credentials can be extracted from the NVS partition of the flash dump using a script that retrieves strings containing the Wi-Fi password.

Added: Dec 10, 2025, 9:25 PM
Updated: Dec 10, 2025, 9:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.