CVE-2025-3652: medium-severity vulnerability in Petlibrio Smart Pet Feeder Platform
Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Petlibrio · Smart Pet Feeder PlatformRelated CVEs — Petlibrio Smart Pet Feeder Platform
In the same product, most dangerous first.
CVE-2025-15115MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpointEPSS 0.3%CVE-2025-3654MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpointEPSS 0.3%CVE-2025-3653MEDIUMPetlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpointEPSS 0.3%CVE-2025-3646MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share APIEPSS 0.2%CVE-2025-3660MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpointEPSS 0.2%