CVE-2025-3646: Missing Authentication for Critical Function in Petlibrio Smart Pet Feeder Platform
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.
AI Analysis
Technical Summary
CVE-2025-3646 is an authorization bypass vulnerability in the Petlibro Smart Pet Feeder Platform affecting versions up to 1.7.31. The vulnerability arises from missing authentication checks on critical functions within the device share API, allowing unauthenticated attackers to add users as shared owners to devices. This bypass enables unauthorized access to devices and exposure of owner information without valid permission validation. The CVSS 4.0 base score is 6.9, indicating a medium severity level with network attack vector and no required privileges or user interaction.
Potential Impact
Exploitation of this vulnerability allows attackers to gain unauthorized access to smart pet feeder devices by adding themselves as shared owners. This unauthorized access can lead to exposure of owner information and potential control over the device without authentication. The impact is limited to confidentiality and authorization bypass but does not include system compromise or denial of service based on the available data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the device share API where possible and monitor for unauthorized sharing activity. Avoid exposing the device management interfaces to untrusted networks.
CVE-2025-3646: Missing Authentication for Critical Function in Petlibrio Smart Pet Feeder Platform
Description
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.
CVSS v4.0
Score 6.9medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-3646 is an authorization bypass vulnerability in the Petlibro Smart Pet Feeder Platform affecting versions up to 1.7.31. The vulnerability arises from missing authentication checks on critical functions within the device share API, allowing unauthenticated attackers to add users as shared owners to devices. This bypass enables unauthorized access to devices and exposure of owner information without valid permission validation. The CVSS 4.0 base score is 6.9, indicating a medium severity level with network attack vector and no required privileges or user interaction.
Potential Impact
Exploitation of this vulnerability allows attackers to gain unauthorized access to smart pet feeder devices by adding themselves as shared owners. This unauthorized access can lead to exposure of owner information and potential control over the device without authentication. The impact is limited to confidentiality and authorization bypass but does not include system compromise or denial of service based on the available data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the device share API where possible and monitor for unauthorized sharing activity. Avoid exposing the device management interfaces to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T13:13:26.337Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6959a9dfdb813ff03e731c9b
Added to database: 01/03/2026, 23:44:31 UTC
Last enriched: 07/21/2026, 18:13:42 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 234
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.