CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-3653: petlibro through 1.7.31 (inclusive); +1 more affected products

CVE-2025-3653. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.00253 (percentile 0.15284), scored 2026-10-05.

Affected technology

petlibro · through 1.7.31 (inclusive)
petlibro

Smart Pet Feeder Platform · 0 through 1.7.31
Petlibrio

Description’s affected range: versions up to 1.7.31

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can control any device by sending serial numbers to device control APIs to change feeding schedules, trigger manual feeds, access camera feeds, and modify device settings without authorization checks. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality, integrity and availability impact as low.

Published

CWE
CWE-612
CCR priority
39.3 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00253 · percentile 0.15366 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-3653.html