6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.
Basic Information
ID
CVE-2025-3646
Source
VulnCheck
Published
Jan 3, 2026 at 23:33
Affected Product
Vendor
Petlibrio
Product
Smart Pet Feeder Platform
Version
Unknown
Affected Versions
Petlibrio Smart Pet Feeder Platform Unknown