---
id: CVE-2025-3646
title: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an
  authorization bypass vulnerability that allows unauthorized users to add users
  as shared owners to any device by exploiting missing permission checks
summary: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an
  authorization bypass vulnerability that allows unauthorized users to add users
  as shared owners to any device by exploiting missing permission checks.
  Attackers can sen…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-306
vendor: petlibro
product: petlibro
affected:
  - petlibro <= 1.7.31
published: '2026-01-04'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3646'
references:
  - url: 'https://bobdahacker.com/blog/petlibro'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-authorization-bypass-via-device-share-api
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00223
epssPercentile: 0.11512
ingestedAt: '2026-07-20T23:44:01.992Z'
---

## Overview

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.

## Affected

- `petlibro <= 1.7.31`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
