CVE-2025-29629

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
Configurations

No configuration.

History

25 Feb 2026, 21:16

Type Values Removed Values Added
CWE CWE-1392
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.1
Summary (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
References
  • {'url': 'http://gardyn.com', 'source': 'cve@mitre.org'}

25 Feb 2026, 17:25

Type Values Removed Values Added
References
  • () https://mygardyn.com/blog/security-update/ -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03 -
Summary (en) An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via the Gardyn Home component (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Un problema en Gardyn 4 permite que un atacante remoto obtenga información confidencial y ejecute código arbitrario a través del componente Gardyn Home

25 Jul 2025, 19:15

Type Values Removed Values Added
CWE CWE-200
CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

25 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-29629

Mitre link : CVE-2025-29629

CVE.ORG link : CVE-2025-29629


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor