CVE-2019-16733: Petwant Pf-103 Firmware

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.

Affected products

  • Petwant Pf-103 Firmware: version 4.22.2.42 only
  • Skymee Petalk Ai Firmware: version 3.2.2.30 only

Published 2019-12-13. Last modified 2026-06-17.