CVE-2025-3653: Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification. Attackers can control any device by sending serial numbers to device control APIs to change feeding schedules, trigger manual feeds, access camera feeds, and modify device settings without authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Petlibro Smart Pet Feeder Platformto a version that resolves this vulnerability.Fixed in 1.7.31 - Compensating control
Restrict access to the device control APIs by ensuring requests are authorized for the device owner; do not accept arbitrary serial numbers without ownership verification.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3653?
CVE-2025-3653 is categorized as a high severity vulnerability due to its potential for unauthorized device manipulation.
How do I fix CVE-2025-3653?
To mitigate CVE-2025-3653, update the Petlibro Smart Pet Feeder Platform to version 1.7.32 or later.
What type of vulnerability is CVE-2025-3653?
CVE-2025-3653 is an improper access control vulnerability that allows unauthorized manipulation of devices.
Who is affected by CVE-2025-3653?
Users of the Petlibro Smart Pet Feeder Platform versions up to 1.7.31 are affected by CVE-2025-3653.
Can CVE-2025-3653 lead to data theft?
While CVE-2025-3653 primarily allows device control, it may indirectly lead to data theft if unauthorized actions are taken.