6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification. Attackers can control any device by sending serial numbers to device control APIs to change feeding schedules, trigger manual feeds, access camera feeds, and modify device settings without authorization checks.
Basic Information
ID
CVE-2025-3653
Source
VulnCheck
Published
Jan 3, 2026 at 23:33
Affected Product
Vendor
Petlibrio
Product
Smart Pet Feeder Platform
Version
Unknown
Affected Versions
Petlibrio Smart Pet Feeder Platform Unknown