Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-29628 PoC — Gardyn 4 安全漏洞

Source
Associated Vulnerability
Title: Gardyn 4 安全漏洞 (CVE-2025-29628)
Description:A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.
Description
CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631
Readme
## Summary

In February 2025 I conducted security research on a Gardyn Home 4.0 device. During my research, I discovered multiple vulnerabilities and poor security practices. By leveraging these vulnerabilities an attacker may be able to gain system level access to a Gardyn device and use it to stage further attacks against the local area network it is connected to. An attacker may also use this access to affect the normal operation of the device, including damaging the plants being grown in the device and the device itself.

This repository contains the technical details and status for a collection of vulnerabilities in the Gardyn hydroponics garden. This information is being released with the purpose if informing consumers with unresolved issues in the security of the Gardyn product. 

## Disclosure Timeline

2025-02-21 - Initial contact with vendor attempted.
2025-02-26 - Contact made with vendor sales team.
2025-04-07 - Contact made with vendor technical representative. Technical details of all vulnerabilities disclosed.
2025-06-14 - Follow up attempted with vendor regarding existing vulnerabilties.



*as of 2025-07-04*

| **CVE**        | **Issue**                | **Status**                                                                                                           |
| -------------- | ------------------------ | -------------------------------------------------------------------------------------------------------------------- |
| CVE-2025-29629 | Weak Default Credentials | The credentials are still the same, but password authentication has been disabled for SSH                            |
| CVE-2025-29630 | SSH Key Backdoor         | An SSH authorized key still exists but has been scrubbed of personally identifying information of a Gardyn Employee. |
| CVE-2025-29628 | Full device takeover     | Unpatched                                                                                                            |
| CVE-2025-29631 | Command Injection        | Unpatched                                                                                                            |
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →