CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
-
Updated
Apr 3, 2026
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-1242: Hardcoded iothubowner Connection String — Gardyn Home Kit (VU#653116)
CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (VU#653116)
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
CISA Advisory ICSA-26-055-03 (Update A) — Gardyn Home Kit IoT Vulnerabilities — 10 CVEs (CVE-2025-1242, CVE-2025-10681, CVE-2025-29628, CVE-2025-29629, CVE-2025-29631, CVE-2026-28766, CVE-2026-25197, CVE-2026-32646, CVE-2026-28767, CVE-2026-32662)
Add a description, image, and links to the gardyn topic page so that developers can more easily learn about it.
To associate your repository with the gardyn topic, visit your repo's landing page and select "manage topics."