Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gardyn — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting Gardyn. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gardyn operates as an IoT plant-growing system with automated monitoring and control capabilities. Historically, the platform has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues across its web interface and mobile applications. The 10 documented CVEs reveal consistent weaknesses in input validation and access control mechanisms. While no major public security incidents have been reported, the pattern of vulnerabilities suggests potential for unauthorized device control and data breaches. The system's internet-connected nature combined with these security concerns presents risks to both user privacy and network security, particularly in environments where the device is connected to larger networks.

CVE ID Title CVSS Severity Published
CVE-2026-54477 Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax — Gardyn Home Firmware CWE-644 5.4 Medium 2026-07-02
CVE-2026-55726 Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere — Gardyn Home Firmware CWE-497 5.3 Medium 2026-07-02
CVE-2026-13768 Gardyn IoT Hub Use of Hard-coded Credentials — Gardyn Home Firmware CWE-798 10.0 Critical 2026-07-02
CVE-2025-10681 Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials — Mobile Application CWE-798 8.6 High 2026-04-03
CVE-2026-25197 Gardyn Cloud API Authorization Bypass Through User-Controlled Key — Cloud API CWE-639 9.1 Critical 2026-04-03
CVE-2026-28766 Gardyn Cloud API Missing Authentication for Critical Function — Cloud API CWE-306 9.3 Critical 2026-04-03
CVE-2026-28767 Gardyn Cloud API Missing Authentication for Critical Function — Cloud API CWE-306 5.3 Medium 2026-04-03
CVE-2026-32646 Gardyn Cloud API Missing Authentication for Critical Function — Cloud API CWE-306 7.5 High 2026-04-03
CVE-2026-32662 Gardyn Cloud API Active Debug Code — Cloud API CWE-489 5.3 Medium 2026-04-03
CVE-2025-1242 Administrative Credentials Can Be Extracted Through Gardyn API Responses — Home Kit CWE-798 9.1 Critical 2026-02-25
CVE-2025-29629 Gardyn 4 安全漏洞 — Home Kit Firmware CWE-1392 9.1 Critical 2025-07-25
CVE-2025-29631 Gardyn 4安全漏洞 — Home Kit Firmware CWE-78 9.8 Critical 2025-07-25
CVE-2025-29628 Gardyn 4 安全漏洞 — Home Kit Firmware CWE-924 9.4 Critical 2025-07-25

This page lists every published CVE security advisory associated with Gardyn. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.