PT-2026-1182 · Petlibro · Petlibro Smart Pet Feeder Platform

·

CVE-2025-3654

·

Published

2026-01-03

·

Updated

2026-07-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Petlibro Smart Pet Feeder Platform versions up to 1.7.31
Description The Petlibro Smart Pet Feeder Platform is affected by an information disclosure issue. This allows unauthorized access to device hardware information. An attacker can obtain device serial numbers and MAC addresses by exploiting insecure API endpoints. The /device/devicePetRelation/getBoundDevices API endpoint is vulnerable, allowing retrieval of information using pet IDs. This enables full device control without proper authorization.
Recommendations Update to a version later than 1.7.31.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3654

Affected Products

Petlibro Smart Pet Feeder Platform