Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13768— Gardyn IoT Hub Use of Hard-coded Credentials

Quick assessment

Affected
Gardyn Gardyn Home Firmware
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gardyn Gardyn Cloud API是美国Gardyn公司的一款连接 Gardyn 设备、手机 App 与云端后端的接口,用于远程控制、数据同步和用户账户管理。 Gardyn Cloud API 2.12.2026之前版本、Gardyn Home Firmware master.627之前版本和Gardyn Studio Firmware master.627之前版本存在信任管理问题漏洞,该漏洞源于暴露了特权的iothubowner密钥,可能导致恶意用户调用IoTHub Registry Man

CVSS 10.0 · Critical EPSS 0.65% · P49

Affected Version Matrix 3

VendorProduct Version RangeStatus
Gardyn Gardyn Cloud API < 2.12.2026 affected
Gardyn Gardyn Home Firmware < master.627 affected
Gardyn Gardyn Studio Firmware < master.627 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13768

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gardyn IoT Hub Use of Hard-coded Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5
Vulnerability Title
Gardyn Cloud API 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Gardyn Gardyn Cloud API是美国Gardyn公司的一款连接 Gardyn 设备、手机 App 与云端后端的接口,用于远程控制、数据同步和用户账户管理。 Gardyn Cloud API 2.12.2026之前版本、Gardyn Home Firmware master.627之前版本和Gardyn Studio Firmware master.627之前版本存在信任管理问题漏洞,该漏洞源于暴露了特权的iothubowner密钥,可能导致恶意用户调用IoTHub Registry Man
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Gardyn Gardyn Home Firmware 0 ~ master.627 -
Gardyn Gardyn Studio Firmware 0 ~ master.627 -
Gardyn Gardyn Cloud API 0 ~ 2.12.2026 -

II. Public POCs for CVE-2026-13768

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13768

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-13768 (2)

Same Patch Batch · Gardyn · 2026-07-02 · 3 CVEs total

CVE-2026-54477 5.4 MEDIUM Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-55726 5.3 MEDIUM Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere

IV. Related Vulnerabilities

V. Comments for CVE-2026-13768

No comments yet


Leave a comment