Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-13768: Gardyn IoT Hub Exposes Sensitive Device Credentials

CVE-2026-13768 CVE-2026-13768
Summary

Gardyn IoT devices have a security flaw that allows hackers to access sensitive information about all connected devices and potentially take control of them. This could lead to unauthorized access to your network and potentially allow hackers to move to other devices. It's recommended to update your Gardyn devices to the latest software version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gardyn gardyn home firmware < master.627
gardyn gardyn studio firmware < master.627
gardyn gardyn cloud api < 2.12.2026
Original title
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn ...
Original description
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
nvd CVSS3.1 10.0
nvd CVSS4.0 9.5
Vulnerability type
CWE-798 Use of Hard-coded Credentials
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026