CVE-2025-3654 is a medium-severity information disclosure vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. The vulnerability allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through /device/devicePetRelation/getBoundDevices using pet IDs, enabling full device control with [truncated]
CVE-2025-3653 is an improper access control vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. This issue allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification, potentially enabling attackers to control any device by sending serial numbers to device control APIs. This could lead to changes in feeding schedules, triggering manua [truncated]
The CVE record for CVE-2025-3652 was published on 2026-01-04T00:15:43.950Z and has not been modified since then. The NVD entry is currently Analyzed. This information disclosure vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31 allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to [truncated]
The CVE-2025-3646 debrief provides an in-depth analysis of the authorization bypass vulnerability in Petlibro Smart Pet Feeder Platform versions up to 1.7.31. The vulnerability allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. This could lead to unauthorized access to devices and sensitive information. The vulnerability has a CVSS score of 6.9 a [truncated]
The Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability. This CVE was published on 2026-01-04T00:15:43.573Z and was last modified on 2026-07-20T23:16:54.303Z. The vulnerability allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thi [truncated]