PatchSiren cyber security CVE debrief
CVE-2025-15115 Petlibrio CVE debrief
The Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability. This CVE was published on 2026-01-04T00:15:43.573Z and was last modified on 2026-07-20T23:16:54.303Z. The vulnerability allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification. Security teams should assess the impact of this vulnerability on their systems and take appropriate mitigation measures.
- Vendor
- Petlibrio
- Product
- Smart Pet Feeder Platform
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-04
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-01-04
- Advisory updated
- 2026-07-20
Who should care
Security teams and administrators responsible for Petlibro Smart Pet Feeder Platform versions up to 1.7.31 should assess and mitigate this authentication bypass vulnerability. They should review system configurations, update to the latest version if available, and implement additional security measures such as monitoring for suspicious activity.
Technical summary
The Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification. This vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity.
Defensive priority
Medium priority given the CVSS score of 6.9 and the potential for unauthorized access.
Recommended defensive actions
- Review and update Petlibro Smart Pet Feeder Platform to version above 1.7.31
- Implement additional authentication and authorization checks for social login system
- Monitor for suspicious activity on /member/auth/thirdLogin endpoint
- Consider compensating controls such as IP restrictions or rate limiting
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence from official CVE and NVD sources indicate an authentication bypass vulnerability exists in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. Limited details are available on exploitability and impacted scope. Further verification is needed to determine the extent of the vulnerability and potential impact on specific systems.
Official resources
-
CVE-2025-15115 CVE record
CVE.org
-
CVE-2025-15115 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-04T00:15:43.573Z and has not been modified since then.