As cited
Copy frozen at (site build).
vulnerabilities
Gardyn IoT Hub
Gardyn IoT Hub devices contain three critical vulnerabilities affecting Home Firmware, Studio Firmware, and Cloud API versions below 2.12.2026. The flaws include exposure of hard-coded credentials, publicly accessible device logs in Azure Blob Storage, and improper HTTP header handling, potentially allowing unauthenticated attackers to control devices and access sensitive information. Gardyn has patched the cloud infrastructure and recommends users ensure Internet connectivity for automatic firmware updates and update their mobile application.
Why it matters: These critical vulnerabilities enable unauthenticated remote control of Gardyn devices and access to all device logs; prioritize updating firmware and ensuring cloud-side patches are active.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Gardyn IoT Hub
Gardyn IoT Hub firmware versions prior to 2.12.2026 contain three critical vulnerabilities including hard-coded credentials (CVE-2026-13768), publicly accessible Azure Blob Storage logs (CVE-2026-55726), and an incomplete third vulnerability (CVE-2026-54477). An unauthenticated attacker could exploit the hard-coded iothubowner key to access device connection information, execute arbitrary commands on connected devices, and potentially pivot across a user's network. Gardyn has updated its deployed infrastructure and released automatic firmware updates for affected Home and Studio devices.
Why it matters: Users of Gardyn IoT Hub systems should verify their devices have downloaded the latest firmware and mobile app updates, as unauthenticated remote attackers can currently control connected devices and access sensitive logs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Gardyn IoT Hub
Gardyn IoT Hub firmware versions prior to 2.12.2026 contain three critical vulnerabilities including hard-coded credentials (CVE-2026-13768), publicly accessible Azure Blob Storage logs (CVE-2026-55726), and an incomplete third vulnerability (CVE-2026-54477). An unauthenticated attacker could exploit the hard-coded iothubowner key to access device connection information, execute arbitrary commands on connected devices, and potentially pivot across a user's network. Gardyn has updated its deployed infrastructure and released automatic firmware updates for affected Home and Studio devices.
Why it matters: Users of Gardyn IoT Hub systems should verify their devices have downloaded the latest firmware and mobile app updates, as unauthenticated remote attackers can currently control connected devices and access sensitive logs.
- Source published
- First seen by Cybersecurity Tracker