Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
References
Configurations
No configuration.
History
03 Jul 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-03 00:16
Updated : 2026-07-06 19:42
NVD link : CVE-2026-13768
Mitre link : CVE-2026-13768
CVE.ORG link : CVE-2026-13768
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
