Unauthenticated attackers can remotely control Gardyn IoT devices via critical command execution flaw
Gardyn has released urgent firmware updates to address a critical vulnerability that allows unauthenticated users to take remote control of Home and Studio devices. The flaw exposes a privileged key that can be used to execute arbitrary commands and potentially pivot into home networks. Ensure your device is running firmware version 619 or later immediately.
Summary
Gardyn has deployed security updates across its ecosystem following the discovery of several high-severity vulnerabilities affecting Gardyn Home and Gardyn Studio devices. The flaws, identified by a third-party researcher, range from critical remote command execution to unauthorized access to device logs and demographic information.
While Gardyn reports no evidence that these vulnerabilities have been exploited in the wild, the company coordinated its response with CISA to remediate the issues before public disclosure. The vulnerabilities primarily affect devices currently connected to the internet.
Technical details
The most severe flaw, CVE-2026-13768 (CVSS 10.0), stems from the exposure of a privileged iothubowner key within the Gardyn Home firmware. An attacker possessing this key can invoke an IoTHub Registry Manager function to retrieve connection information for all connected Gardyn Home Kit and Studio devices. This access further enables the execution of arbitrary commands on specific connected devices and provides a potential path to pivot to other devices residing on the user's local network.
Two additional vulnerabilities impact data privacy:
- CVE-2026-55726 (CVSS 5.3): An Azure Blob Storage container used for device logs is publicly listable without authentication, allowing access to any log files stored within the container.
- CVE-2026-54477 (CVSS 5.4): The device admin panel lacks standard security headers, which could facilitate clickjacking or cross-site scripting attacks.
If exploited, these flaws could allow unauthorized users to alter plant care functions, such as lighting or watering schedules, and potentially access demographic information including names, addresses, phone numbers, and email addresses.
Affected products and fixed versions
The vulnerabilities affect the Gardyn Home and Gardyn Studio ecosystem. Fixes are deployed automatically to any device that connects to the internet.
| Component | Required Version for Fix |
|---|---|
| Gardyn Device Firmware | 619 or later |
| Gardyn Mobile App | 2.11.0 or later |
Defender guidance
To secure your hardware, verify your current versions through the Gardyn mobile app by navigating to Settings → Advanced.
- Verify Firmware: Ensure your device is running version 619 or higher.
- Update Mobile App: Ensure your mobile application is version 2.11.0 or later.
- Restore Connectivity: If your device has been offline, reconnect it to the internet to trigger the automatic update process.
- Network Hardening: As a precaution against potential local network exposure, Gardyn suggests users may reset their Wi-Fi passwords if they have concerns regarding local configuration data.
What remains unclear
While Gardyn states that no evidence of exploitation has been found, it is not yet confirmed whether the publicly listable Azure Blob Storage container was accessed by unauthorized parties prior to the fix being implemented. Additionally, while the company notes that payment card data is not stored on their systems, the full scope of what specific local network configuration data could have been viewed via a compromised device remains unconfirmed.
#h4rithd #news #HarithDilshan #IoT #Gardyn #Cybersecurity #Infosec
