CVE-2025-3646

Source
https://cve.org/CVERecord?id=CVE-2025-3646
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3646.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3646
Published
2026-01-04T00:15:43.783Z
Modified
2026-03-12T20:20:04.606724Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3646.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.7.31"
            }
        ]
    }
]