CVE-2025-3654CWE-612

Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint

Medium · published January 3, 2026

CVSS v4.0
6.9
EPSS
0%
Percentile
19.5
In the wild
Unconfirmed
What it is

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through /device/devicePetRelation/getBoundDevices using pet IDs, enabling full device control without proper authorization checks.

The record
Technical detail
CVSS v4.0
6.9 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00274 · 19.5th percentile
Weakness
CWE-612 · Improper Authorization of Index Containing Sensitive Information
Published
2026-01-03T23:33Z
EPSS history
Timeline
  • 03 JAN 23:33Z
    Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
    cvelistv5