CVE-2025-3646: Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Petlibro Smart Pet Feeder Platformto a version that resolves this vulnerability.Fixed in 1.7.31
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3646?
CVE-2025-3646 is rated as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-3646?
To fix CVE-2025-3646, update the Petlibro Smart Pet Feeder Platform to version 1.7.32 or later.
What impact does CVE-2025-3646 have on users?
CVE-2025-3646 allows unauthorized users to add shared owners to devices, potentially leading to unauthorized control.
Which versions are affected by CVE-2025-3646?
CVE-2025-3646 affects Petlibro Smart Pet Feeder Platform versions up to and including 1.7.31.
What type of vulnerability is CVE-2025-3646?
CVE-2025-3646 is an authorization bypass vulnerability.