top of page
perceptive_background_267k.jpg

Gardyn IoT Hub

Published:

2 juli 2026 om 12:00:00

Alert date:

2 juli 2026 om 17:05:10

Source:

cisa.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure, Identity & Access, Web Technologies

CISA released an ICS advisory for Gardyn IoT Hub identifying three vulnerabilities affecting Home Firmware, Studio Firmware, and Cloud API versions prior to 2.12.2026. The most critical vulnerability (CVE-2026-13768, CVSS 10) involves exposed hard-coded iothubowner credentials allowing unauthenticated remote code execution on connected devices and potential lateral movement. CVE-2026-55726 exposes Azure Blob Storage device logs publicly without authentication. CVE-2026-54477 affects the admin panel with missing security headers enabling clickjacking and XSS attacks. All vulnerabilities affect the Food and Agriculture critical infrastructure sector deployed in the United States. Gardyn has patched the infrastructure and recommends users ensure devices have internet connectivity for automatic firmware updates. No known public exploitation has been reported at the time of publication.

Technical details

Mitigation steps:

Affected products:

Gardyn IoT Hub
Gardyn Home Firmware
Gardyn Studio Firmware
Gardyn Cloud API

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page