Junglewise Threat Intelligence

CVE-2025-15115: Petlibro Smart Pet Feeder Platform authentication bypass in social login API

CVE-2025-15115 · Severity: medium · CVSS 6.5 · Published 2026-01-04

Technologies: Petlibro Smart Pet Feeder Platform, Petlibro. Vendors: Petlibro.

Executive brief

Petlibro smart pet feeders and fountains, used by millions of pet owners to manage feeding and monitoring remotely, are affected by a critical security flaw. An attacker can bypass security checks to log into any user account, allowing them to hijack devices, view camera feeds, listen to private audio recordings, and change feeding schedules. This could lead to unauthorized access to a user's home environment and potential harm to pets if feeding schedules are maliciously altered.

Technical details

An authentication bypass exists in the Petlibro API endpoint `/member/auth/thirdLogin` due to a failure to verify OAuth tokens server-side. The application incorrectly treats a user's Google ID (which is public information) as a secret credential. An unauthenticated attacker can provide an arbitrary Google ID and `phoneBrand` parameter to the vulnerable endpoint to receive a valid session token for the targeted account. While a fix was developed, the vendor reportedly left the vulnerable legacy endpoint active to maintain compatibility with older app versions, leaving accounts exposed. Successful exploitation allows full account takeover, including access to pet data, device serial numbers, camera feeds, and private audio recordings.

Affected products

  • Petlibro Smart Pet Feeder Platform up to 1.7.31

Timeline

  • 2025-11-05: disclosed: Initial report to vendor by security researcher.
  • 2025-12-04: patched: Vendor claimed majority of issues resolved but kept vulnerable endpoint for legacy support.
  • 2026-01-03: advisory: CVE published.

References

Related threats