Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-13768: Gardyn IoT Hub Exposes Sensitive Device Credentials
CVE-2026-13768
CVE-2026-13768
Summary
Gardyn IoT devices have a security flaw that allows hackers to access sensitive information about all connected devices and potentially take control of them. This could lead to unauthorized access to your network and potentially allow hackers to move to other devices. It's recommended to update your Gardyn devices to the latest software version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gardyn | gardyn home firmware | < master.627 |
| gardyn | gardyn studio firmware | < master.627 |
| gardyn | gardyn cloud api | < 2.12.2026 |
Original title
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn ...
Original description
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
nvd CVSS3.1
10.0
nvd CVSS4.0
9.5
Vulnerability type
CWE-798
Use of Hard-coded Credentials
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026