


Perceptive Security
SOC/SIEM Consultancy

Gardyn IoT Hub
Published:
2 juli 2026 om 12:00:00
Alert date:
2 juli 2026 om 17:05:10
Source:
cisa.gov
Mobile & IoT, Critical Infrastructure, Identity & Access, Web Technologies
CISA released an ICS advisory for Gardyn IoT Hub identifying three vulnerabilities affecting Home Firmware, Studio Firmware, and Cloud API versions prior to 2.12.2026. The most critical vulnerability (CVE-2026-13768, CVSS 10) involves exposed hard-coded iothubowner credentials allowing unauthenticated remote code execution on connected devices and potential lateral movement. CVE-2026-55726 exposes Azure Blob Storage device logs publicly without authentication. CVE-2026-54477 affects the admin panel with missing security headers enabling clickjacking and XSS attacks. All vulnerabilities affect the Food and Agriculture critical infrastructure sector deployed in the United States. Gardyn has patched the infrastructure and recommends users ensure devices have internet connectivity for automatic firmware updates. No known public exploitation has been reported at the time of publication.
Technical details
Mitigation steps:
Affected products:
Gardyn IoT Hub
Gardyn Home Firmware
Gardyn Studio Firmware
Gardyn Cloud API
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json
https://www.cve.org/CVERecord?id=CVE-2026-13768
https://www.cve.org/CVERecord?id=CVE-2026-55726
https://www.cve.org/CVERecord?id=CVE-2026-54477
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
https://mygardyn.com/security/
mailto:support@mygardyn.com
https://cwe.mitre.org/data/definitions/798.html
https://cwe.mitre.org/data/definitions/497.html
https://cwe.mitre.org/data/definitions/644.html
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
