Junglewise Threat Intelligence

CVE-2025-3653: Petlibro Smart Pet Feeder improper access control in API

CVE-2025-3653 · Severity: high · CVSS 7.3 · Published 2026-01-04

Technologies: Petlibro Smart Pet Feeder Platform, Petlibro. Vendors: Petlibro.

Executive brief

Petlibro smart pet feeders, which allow owners to remotely feed and monitor pets, suffer from a security flaw that allows unauthorized control of the devices. An attacker can remotely change feeding schedules, trigger manual feedings, and access live camera feeds or private audio recordings. This could lead to pet health issues if feeding is disrupted or a significant invasion of privacy within the home.

Technical details

The Petlibro Smart Pet Feeder Platform (up to version 1.7.31) fails to perform ownership verification on several API endpoints, most notably those handling device control and pet data. By supplying a valid device serial number to the device control APIs, an unauthenticated attacker can modify feeding schedules, trigger manual feeds, and access camera streams. Serial numbers and MAC addresses can be harvested via the /device/devicePetRelation/getBoundDevices endpoint using a pet ID, which itself is accessible via the /member/pet/detailV2 endpoint without authorization checks. Additionally, the platform is susceptible to account takeover via a legacy social login endpoint (/member/auth/thirdLogin) that accepts Google IDs without verifying OAuth tokens.

Affected products

  • Petlibro Smart Pet Feeder Platform up to 1.7.31

Timeline

  • 2025-11-05: disclosed: Initial report to vendor by researcher BobDaHacker.
  • 2025-12-04: patched: Vendor claimed majority of issues resolved, though legacy auth endpoint remained active.
  • 2026-01-03: advisory: CVE published.

References

Related threats