目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-29628 PoC — Gardyn 4 安全漏洞

来源
关联漏洞
标题: Gardyn 4 安全漏洞 (CVE-2025-29628)
Description:Gardyn 4是美国Gardyn公司的一种家用垂直水培种植系统。 Gardyn 4存在安全漏洞,该漏洞源于请求处理不当,可能导致信息泄露和执行任意代码。
Description
CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631
介绍
## Summary

In February 2025 I conducted security research on a Gardyn Home 4.0 device. During my research, I discovered multiple vulnerabilities and poor security practices. By leveraging these vulnerabilities an attacker may be able to gain system level access to a Gardyn device and use it to stage further attacks against the local area network it is connected to. An attacker may also use this access to affect the normal operation of the device, including damaging the plants being grown in the device and the device itself.

This repository contains the technical details and status for a collection of vulnerabilities in the Gardyn hydroponics garden. This information is being released with the purpose if informing consumers with unresolved issues in the security of the Gardyn product. 

## Disclosure Timeline

2025-02-21 - Initial contact with vendor attempted.
2025-02-26 - Contact made with vendor sales team.
2025-04-07 - Contact made with vendor technical representative. Technical details of all vulnerabilities disclosed.
2025-06-14 - Follow up attempted with vendor regarding existing vulnerabilties.



*as of 2025-07-04*

| **CVE**        | **Issue**                | **Status**                                                                                                           |
| -------------- | ------------------------ | -------------------------------------------------------------------------------------------------------------------- |
| CVE-2025-29629 | Weak Default Credentials | The credentials are still the same, but password authentication has been disabled for SSH                            |
| CVE-2025-29630 | SSH Key Backdoor         | An SSH authorized key still exists but has been scrubbed of personally identifying information of a Gardyn Employee. |
| CVE-2025-29628 | Full device takeover     | Unpatched                                                                                                            |
| CVE-2025-29631 | Command Injection        | Unpatched                                                                                                            |
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →