CVE-2025-3654: Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through /device/devicePetRelation/getBoundDevices using pet IDs, enabling full device control without proper authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Petlibro Smart Pet Feeder Platformto a version that resolves this vulnerability.Fixed in 1.7.31
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3654?
CVE-2025-3654 is identified as a medium severity vulnerability due to the risk of information disclosure.
How do I fix CVE-2025-3654?
To mitigate CVE-2025-3654, update the Petlibro Smart Pet Feeder Platform to a version above 1.7.31.
What information can be accessed through CVE-2025-3654?
CVE-2025-3654 allows attackers to retrieve sensitive device information such as serial numbers and MAC addresses.
Which versions of the Petlibro Smart Pet Feeder Platform are affected by CVE-2025-3654?
CVE-2025-3654 affects all versions of the Petlibro Smart Pet Feeder Platform up to and including 1.7.31.
What causes the CVE-2025-3654 vulnerability?
CVE-2025-3654 is caused by insecure API endpoints that enable unauthorized access to device hardware information.