Junglewise Threat Intelligence

CVE-2025-3660: Petlibro Smart Pet Feeder Platform broken access control in API

CVE-2025-3660 · Severity: medium · CVSS 6.5 · Published 2026-01-04

Technologies: Petlibro Smart Pet Feeder Platform, Petlibro. Vendors: Petlibro.

Executive brief

Petlibro's smart pet feeder platform, used to manage automated feeding and monitoring devices, contains a security flaw that allows unauthorized access to user data. An attacker can exploit this to view private information about other people's pets, including health data, photos, and owner account details. In more severe cases, this could lead to full account takeover, allowing unauthorized individuals to control feeding schedules or access home camera feeds.

Technical details

A broken access control vulnerability exists in the Petlibro Smart Pet Feeder Platform API endpoint /member/pet/detailV2. The application fails to perform ownership verification, allowing any authenticated user to query the details of any pet by providing an arbitrary pet ID. Successful exploitation grants access to sensitive data including pet names, breeds, birth dates, weights, appetite/activity levels, and associated member IDs. Related research indicates this flaw is part of a broader set of issues including an authentication bypass in /member/auth/thirdLogin and lack of authorization checks on device serial numbers, which could lead to full device hijacking and access to private audio/video feeds. While some fixes have been implemented, legacy endpoints may remain active.

Affected products

  • Petlibro Smart Pet Feeder Platform up to 1.7.31

Timeline

  • 2025-11-05: disclosed: Initial report to vendor by security researcher.
  • 2025-12-04: patched: Vendor claimed majority of issues resolved in latest app version.
  • 2026-01-03: advisory: CVE published to NVD.

References

Related threats