Impact
Gardyn devices embed a privileged iothubowner key, a classic case of hard‑coded credentials (CWE‑798). The key enables an attacker to call an IoTHub Registry Manager function that returns connection information for every Gardyn Home Kit and Studio device. Armed with that information the attacker can execute arbitrary commands on any connected device and potentially pivot to other devices on the user’s network, compromising confidentiality, integrity, and availability across the entire Gardyn ecosystem.
Affected Systems
The vulnerability affects Gardyn Cloud API, Gardyn Home Firmware, and Gardyn Studio Firmware. No specific firmware or API versions are listed, so any instances running the current code before Gardyn’s update may be vulnerable. The vendor notes that the IoT Hub deployed infrastructure has been updated to address these vulnerabilities, but devices must receive the firmware update to be fully secured.
Risk and Exploitability
The CVSS score of 9.5 marks the flaw as critical, while the EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote exploitation over the Internet by using the hard‑coded key to bypass authentication, retrieve device credentials, and issue arbitrary commands via the IoTHub API; this inference is drawn from the description, where the attack path is not explicitly detailed.
OpenCVE Enrichment