CVE-2025-3654
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through /device/devicePetRelation/getBoundDevices using pet IDs, enabling full device control without proper authorization checks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-612
- Published
- 2026-01-03
- Last modified
- 2026-07-20
Affected products
- Petlibrio Smart Pet Feeder Platform
- Petlibrio Smart Pet Feeder Platform
Weakness type
Related vulnerabilities
- CVE-2019-25605 — EquityPandit 1.0 Insecure Logging Information Disclosure
- CVE-2025-3660 — Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
- CVE-2025-3653 — Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
- CVE-2025-57756 — Contao discloses sensitive information in the front end search index
- CVE-2024-49071 — Windows Defender Information Disclosure Vulnerability
- CVE-2024-25635 — IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
- CVE-2023-4560 — Improper Authorization of Index Containing Sensitive Information in omeka/omeka-s
- CVE-2022-41918 — Issue with fine-grained access control of indices backing data streams