Critical Gardyn Smart Gardens Vulnerabilities Let Attackers Control Devices Remotely
ID: 82833e69-49ed-5c82-a672-a72035752f05
STIX ID: report--82833e69-49ed-5c82-a672-a72035752f05
Feed Name: cybersecurityNews.com
CISA issued a high-severity advisory (CVSS up to 9.3) for Gardyn Home Kit smart garden systems detailing critical flaws — including hard-coded/default credentials, cleartext data transmission, OS command injection, missing authentication, and exposed debug functionality — that could allow unauthenticated remote takeover of devices and lateral movement across the Gardyn cloud; affected components include Gardyn firmware, mobile app versions before 2.11.0, and Gardyn Cloud API versions prior to 2.12.2026. CISA recommends immediate patching, network isolation, VPNs for remote access, and other mitigations; there is no current evidence of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
