Junglewise Threat Intelligence

CVE-2025-3654: Petlibro Smart Pet Feeder Platform information disclosure in API

CVE-2025-3654 · Severity: medium · CVSS 5.3 · Published 2026-01-04

Technologies: Petlibro Smart Pet Feeder Platform, Petlibro. Vendors: Petlibro.

Executive brief

Petlibro smart pet feeders, which allow owners to remotely feed and monitor pets, are affected by a security flaw in their cloud platform. An attacker can remotely access sensitive device information, including serial numbers and MAC addresses, without needing to log in. This information can be used as a stepping stone to take control of the feeder, potentially allowing unauthorized individuals to change feeding schedules or access camera feeds.

Technical details

An information disclosure vulnerability exists in the Petlibro Smart Pet Feeder Platform API due to improper authorization checks. Specifically, the /device/devicePetRelation/getBoundDevices endpoint allows unauthenticated attackers to retrieve sensitive hardware identifiers, such as device serial numbers and MAC addresses, by supplying a pet ID. Because subsequent device control APIs rely on these serial numbers for identification without verifying ownership, an attacker can leverage this disclosed information to achieve unauthorized control over the pet feeder, including modifying feeding schedules and accessing camera streams. The vendor has reportedly introduced a fix in later versions, though some legacy endpoints remained active during the disclosure process.

Affected products

  • Petlibro Smart Pet Feeder Platform up to 1.7.31

Timeline

  • 2025-11-05: disclosed: Initial report to vendor by security researcher
  • 2025-12-04: patched: Vendor claimed majority of issues resolved in latest app version
  • 2026-01-03: advisory: CVE published by VulnCheck

References

Related threats