CVE-2025-3654 | Petlibrio Smart Pet Feeder Platform up to 1.7.31 API Endpoint getBoundDevices improper authorization of index containing sensitive information (EUVD-2026-0784 / CNNVD-202601-788)
A vulnerability identified as problematic has been detected in Petlibrio Smart Pet Feeder Platform up to 1.7.31. The impacted element is an unknown function of the file /device/devicePetRelation/getBoundDevices of the component API Endpoint. The manipulation leads to improper authorization of index containing sensitive information.
This vulnerability is uniquely identified as CVE-2025-3654. The attack is possible to be carried out remotely. No exploit exists.