Gardyn IoT Hub

Plan PatchCVSS 10ICS-CERT ICSA-26-183-03Jul 2, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities (CWE-798: hardcoded credentials, CWE-497: exposed sensitive data, CWE-644: incomplete validation) in Gardyn IoT Hub allow unauthenticated users to access and control managed devices. The vulnerabilities affect Home Firmware versions before master.627, Studio Firmware versions before master.627, and Cloud API versions before 2.12.2026. Gardyn has deployed infrastructure fixes and released firmware updates.

What this means
What could happen
An unauthenticated attacker with network access to a Gardyn IoT Hub could remotely access and control connected smart garden devices, potentially disrupting crop management systems or altering environmental controls like irrigation and lighting schedules.
Who's at risk
Gardyn IoT Hub owners and operators, particularly those managing smart indoor gardens for residential or light commercial use. Affects Home Firmware and Studio Firmware versions prior to master.627, and Cloud API versions prior to 2.12.2026.
How it could be exploited
An attacker on the network (or internet if the device is internet-exposed) can send requests directly to the IoT Hub without credentials due to missing authentication checks. This grants access to the device management API, allowing remote commands to be issued to connected gardening devices.
Prerequisites
  • Network connectivity to the Gardyn IoT Hub (local network or internet if port-forwarded/exposed)
  • No authentication credentials required
remotely exploitableno authentication requiredlow complexitycritical CVSS (10.0)affects IoT device controlunauthenticated access to device management
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Public Proof-of-Concept (PoC) on GitHub (4 repositories)
Affected products (3)
3 pending
ProductAffected VersionsFix Status
Home Firmware<master.627No fix yet
Studio Firmware<master.627No fix yet
Cloud API<2.12.2026No fix yet
Remediation & Mitigation
0/4
Do now
0/3
HOTFIXEnsure all Gardyn IoT Hub devices have active Internet connectivity to receive and install automatic firmware updates
HOTFIXUpdate the Gardyn mobile application to the most recent version available
WORKAROUNDRestrict network access to the Gardyn IoT Hub to trusted devices only; isolate the hub on a separate network segment if possible
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Cloud API
HOTFIXVerify Hub firmware version matches or exceeds master.627 and Cloud API version matches or exceeds 2.12.2026 using the Gardyn App
API: /api/v1/advisories/b7f6354a-d66c-4655-8435-a504edc6fdb6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Gardyn IoT Hub | CVSS 10 - OTPulse