PT-2026-1179 · Petlibro · Petlibro Smart Pet Feeder Platform

Bobdahacker

·

Published

2026-01-03

·

Updated

2026-02-03

·

CVE-2025-3646

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Petlibro Smart Pet Feeder Platform versions up to 1.7.31
Description The Petlibro Smart Pet Feeder Platform is affected by an authorization bypass. This allows unauthorized users to add themselves as shared owners to any device. The issue is due to missing permission checks when processing requests to the device share API. An attacker can exploit this to gain unauthorized access to devices and view owner information without proper authorization.
Recommendations Update to a version later than 1.7.31.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-3646

Affected Products

Petlibro Smart Pet Feeder Platform