PT-2025-30890 · Gardyn 4 · Gardyn 4
Mselbrede
·
Published
2025-07-25
·
Updated
2026-02-27
·
CVE-2025-29631
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gardyn Home Kit firmware versions prior to master.619
Gardyn Home Kit Mobile Application versions prior to 2.11.0
Gardyn Home Kit Cloud API versions prior to 2.12.2026
Gardyn 4 (affected versions not specified)
Description
A flaw exists in Gardyn Home Kits that allows for command injection due to inadequate input sanitization before execution by the operating system. This may allow an attacker to execute arbitrary operating system commands on a target Home Kit. The vulnerability allows a remote attacker to execute arbitrary code.
Recommendations
Update Gardyn Home Kit firmware to version master.619 or later.
Update Gardyn Home Kit Mobile Application to version 2.11.0 or later.
Update Gardyn Home Kit Cloud API to version 2.12.2026 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gardyn 4