PT-2025-30890 · Gardyn 4 · Gardyn 4

Mselbrede

·

Published

2025-07-25

·

Updated

2026-02-27

·

CVE-2025-29631

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gardyn Home Kit firmware versions prior to master.619 Gardyn Home Kit Mobile Application versions prior to 2.11.0 Gardyn Home Kit Cloud API versions prior to 2.12.2026 Gardyn 4 (affected versions not specified)
Description A flaw exists in Gardyn Home Kits that allows for command injection due to inadequate input sanitization before execution by the operating system. This may allow an attacker to execute arbitrary operating system commands on a target Home Kit. The vulnerability allows a remote attacker to execute arbitrary code.
Recommendations Update Gardyn Home Kit firmware to version master.619 or later. Update Gardyn Home Kit Mobile Application to version 2.11.0 or later. Update Gardyn Home Kit Cloud API to version 2.12.2026 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29631

Affected Products

Gardyn 4