CVE-2025-3652

Source
https://cve.org/CVERecord?id=CVE-2025-3652
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3652.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3652
Published
2026-01-04T00:15:43.950Z
Modified
2026-03-12T20:20:04.816559Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3652.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.7.31"
            }
        ]
    }
]