Junglewise Threat Intelligence

CVE-2025-3646: Petlibro Smart Pet Feeder Platform authorization bypass in device share API

CVE-2025-3646 · Severity: high · CVSS 7.3 · Published 2026-01-04

Technologies: Petlibro Smart Pet Feeder Platform, Petlibro. Vendors: Petlibro.

Executive brief

Petlibro's smart pet feeder platform, used to manage automated feeding and monitoring devices, contains a security flaw in its sharing system. An unauthorized person can exploit this to add themselves as a 'shared owner' to any device without the real owner's permission. This allows an attacker to gain control over pet feeders, view owner information, and potentially access camera feeds or feeding schedules, posing a significant privacy and safety risk to pet owners.

Technical details

The vulnerability exists in the Petlibro Smart Pet Feeder Platform's device share API due to a lack of server-side authorization checks (CWE-306). An unauthenticated remote attacker can send a crafted request to the sharing endpoint to add any user account as a shared owner of a target device. This bypasses the intended permission model, granting the attacker unauthorized access to device controls, serial numbers, and owner metadata. While the vendor has reportedly introduced a fix in newer versions, the vulnerability persists in legacy endpoints maintained for backward compatibility. An attacker can leverage this to hijack device functionality, including manual feeding triggers and camera access.

Affected products

  • Petlibro Smart Pet Feeder Platform up to 1.7.31

Timeline

  • 2025-11-05: disclosed: Vulnerability reported to vendor by researcher
  • 2025-12-04: patched: Vendor claimed majority of issues resolved in latest app version
  • 2026-01-03: advisory: CVE published to NVD

References

Related threats