PT-2026-21920 · Gardyn · Gardyn Iot Hub

Published

2026-02-25

·

Updated

2026-04-22

·

CVE-2025-1242

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gardyn IoT Hub (affected versions not specified)
Description Administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. This exposure may allow an attacker to gain full administrative access to the Gardyn IoT Hub, potentially exposing connected devices to malicious control. The vulnerability allows an attacker to extract administrative credentials via multiple attack vectors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-1242

Affected Products

Gardyn Iot Hub