CVE-2025-3653
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification. Attackers can control any device by sending serial numbers to device control APIs to change feeding schedules, trigger manual feeds, access camera feeds, and modify device settings without authorization checks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-612
- Published
- 2026-01-03
- Last modified
- 2026-07-20
Affected products
- Petlibrio Smart Pet Feeder Platform
- Petlibrio Smart Pet Feeder Platform
Weakness type
Related vulnerabilities
- CVE-2019-25605 — EquityPandit 1.0 Insecure Logging Information Disclosure
- CVE-2025-3660 — Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
- CVE-2025-3654 — Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
- CVE-2025-57756 — Contao discloses sensitive information in the front end search index
- CVE-2024-49071 — Windows Defender Information Disclosure Vulnerability
- CVE-2024-25635 — IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
- CVE-2023-4560 — Improper Authorization of Index Containing Sensitive Information in omeka/omeka-s
- CVE-2022-41918 — Issue with fine-grained access control of indices backing data streams