CVE-2025-3652: Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Petlibro Smart Pet Feeder Platformto a version that resolves this vulnerability.Fixed in 1.7.31 - Compensating control
Block or restrict access to the API endpoint /device/deviceAudio/use so that arbitrary audio IDs cannot be assigned to devices and unauthorized users cannot retrieve private audio URLs (enforce via API gateway/WAF/firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3652?
CVE-2025-3652 is classified as a moderate-severity information disclosure vulnerability.
How do I fix CVE-2025-3652?
To fix CVE-2025-3652, upgrade Petlibro Smart Pet Feeder Platform to version 1.7.32 or later.
What types of data are exposed in CVE-2025-3652?
CVE-2025-3652 exposes private audio recordings due to unauthorized access.
Which versions of Petlibro Smart Pet Feeder Platform are affected by CVE-2025-3652?
Petlibro Smart Pet Feeder Platform versions up to and including 1.7.31 are affected by CVE-2025-3652.
What is the attack vector for CVE-2025-3652?
The attack vector for CVE-2025-3652 involves exploiting sequential audio IDs and insecure assignment endpoints.