Petwant manufactures a narrow line of pet-care IoT devices, notably the PF-103 smart feeder and its firmware, which sit in an unexpectedly prominent position in the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including OS command injection, out-of-bounds writes, cleartext transmission, improper cryptographic verification, and missing authentication for critical functions—a pattern reflecting the intersection of embedded firmware, network connectivity, and direct access to physical device control. Defenders managing these devices should treat firmware updates as high-priority and inventory exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Petwant over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16733CRITICAL processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. | Dec 13, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16737CRITICAL The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the | Dec 13, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16734CRITICAL Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root | Dec 13, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-17364CRITICAL The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as t | Dec 13, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-16736CRITICAL A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of | Dec 13, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-16735CRITICAL A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of serv | Dec 13, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-16730CRITICAL processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. | Dec 13, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-16732HIGH Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user. | Dec 13, 2019 | 8.1 | 22 | NO | NO |
CVE-2019-16731HIGH The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings. | Dec 13, 2019 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Petwant.
Media articles that mention a CVE ID that affects a product developed by Petwant — matched by CVE ID, not by vendor name.