PT-2026-55338 · Gardyn · Gardyn Studio+1

·

CVE-2026-13768

·

Published

2026-07-02

·

Updated

2026-07-12

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Gardyn Home Kit and Studio devices (affected versions not specified) Gardyn IoT Hub (affected versions not specified)
Description Gardyn devices and the associated IoT Hub cloud service expose a hardcoded privileged iothubowner key. An unauthenticated attacker can use this key to invoke an IoTHub Registry Manager function to retrieve connection information for all Gardyn Home Kit and Studio devices. Furthermore, this access allows the execution of arbitrary commands on specific connected devices and may enable the attacker to pivot to other devices within the user's local network.
Recommendations Ensure the Gardyn app and device are updated to the most current version. Place smart devices on a separate guest or IoT WiFi network to prevent a compromised device from accessing other devices on the home network.

Fix

RCE

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13768

Affected Products

Gardyn Home Kit
Gardyn Studio