logo

Critical Gardyn Smart Gardens Vulnerabilities Let Attackers Control Devices Remotely

ID: 82833e69-49ed-5c82-a672-a72035752f05

STIX ID: report--82833e69-49ed-5c82-a672-a72035752f05

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA issued a high-severity advisory (CVSS up to 9.3) for Gardyn Home Kit smart garden systems detailing critical flaws — including hard-coded/default credentials, cleartext data transmission, OS command injection, missing authentication, and exposed debug functionality — that could allow unauthenticated remote takeover of devices and lateral movement across the Gardyn cloud; affected components include Gardyn firmware, mobile app versions before 2.11.0, and Gardyn Cloud API versions prior to 2.12.2026. CISA recommends immediate patching, network isolation, VPNs for remote access, and other mitigations; there is no current evidence of active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.