CVE-2025-3652

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:petlibro:petlibro:*:*:*:*:-:*:*:*

History

03 Feb 2026, 17:40

Type Values Removed Values Added
CPE cpe:2.3:a:petlibro:petlibro:*:*:*:*:-:*:*:*
References () https://bobdahacker.com/blog/petlibro - () https://bobdahacker.com/blog/petlibro - Product
References () https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-audio-information-disclosure-via-api-endpoint - () https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-audio-information-disclosure-via-api-endpoint - Third Party Advisory
First Time Petlibro petlibro
Petlibro

Information

Published : 2026-01-04 00:15

Updated : 2026-02-03 17:40


NVD link : CVE-2025-3652

Mitre link : CVE-2025-3652

CVE.ORG link : CVE-2025-3652


JSON object : View

Products Affected

petlibro

  • petlibro
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel