PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15115 Petlibrio CVE debrief

The Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability. This CVE was published on 2026-01-04T00:15:43.573Z and was last modified on 2026-07-20T23:16:54.303Z. The vulnerability allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification. Security teams should assess the impact of this vulnerability on their systems and take appropriate mitigation measures.

Vendor
Petlibrio
Product
Smart Pet Feeder Platform
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-04
Original CVE updated
2026-07-20
Advisory published
2026-01-04
Advisory updated
2026-07-20

Who should care

Security teams and administrators responsible for Petlibro Smart Pet Feeder Platform versions up to 1.7.31 should assess and mitigate this authentication bypass vulnerability. They should review system configurations, update to the latest version if available, and implement additional security measures such as monitoring for suspicious activity.

Technical summary

The Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification. This vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity.

Defensive priority

Medium priority given the CVSS score of 6.9 and the potential for unauthorized access.

Recommended defensive actions

  • Review and update Petlibro Smart Pet Feeder Platform to version above 1.7.31
  • Implement additional authentication and authorization checks for social login system
  • Monitor for suspicious activity on /member/auth/thirdLogin endpoint
  • Consider compensating controls such as IP restrictions or rate limiting
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official CVE and NVD sources indicate an authentication bypass vulnerability exists in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. Limited details are available on exploitability and impacted scope. Further verification is needed to determine the extent of the vulnerability and potential impact on specific systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-04T00:15:43.573Z and has not been modified since then.