PatchSiren cyber security CVE debrief
CVE-2025-3652 Petlibrio CVE debrief
The CVE record for CVE-2025-3652 was published on 2026-01-04T00:15:43.950Z and has not been modified since then. The NVD entry is currently Analyzed. This information disclosure vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31 allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings. The medium CVSS score of 6.9 indicates a moderate risk level, and security teams should be aware of this vulnerability.
- Vendor
- Petlibrio
- Product
- Smart Pet Feeder Platform
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-04
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-01-04
- Advisory updated
- 2026-07-20
Who should care
Security teams responsible for IoT devices, particularly smart pet feeders, should be aware of this vulnerability. The medium CVSS score of 6.9 indicates a moderate risk level. Teams should assess their exposure, implement compensating controls, and monitor for suspicious activity related to audio ID manipulation.
Technical summary
CVE-2025-3652 is an information disclosure vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. The vulnerability allows attackers to access private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Specifically, attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings. This vulnerability has a medium CVSS score of 6.9, indicating a moderate risk level.
Defensive priority
Medium priority due to the moderate CVSS score and potential for unauthorized access to sensitive information.
Recommended defensive actions
- Inventory and assess Petlibro Smart Pet Feeder Platform versions up to 1.7.31 for exposure
- Implement compensating controls to monitor and restrict access to audio recordings
- Apply vendor remediation or patches as available
- Enforce secure assignment and retrieval of audio recordings
- Monitor for suspicious activity related to audio ID manipulation
- Review and update incident response plans to address potential unauthorized access to sensitive information
- Conduct regular security audits to identify and address potential vulnerabilities in IoT devices
Evidence notes
The CVE record and NVD details provide information on the vulnerability. However, further investigation is needed to fully understand the affected scope and potential impact. Limited information is available on known affected systems or vendor remediation efforts. Additional research is required to determine the extent of the vulnerability and potential mitigations.
Official resources
-
CVE-2025-3652 CVE record
CVE.org
-
CVE-2025-3652 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-04T00:15:43.950Z and has not been modified since then. The NVD entry is currently Analyzed.