CVE-2025-29629

G

ardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

Configurations

No configuration.

History

25 Feb 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.1
CWE CWE-1392
References
Summary (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

25 Feb 2026, 17:25

Type Values Removed Values Added
References
  • () https://mygardyn.com/blog/security-update/ -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03 -
Summary (en) An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via the Gardyn Home component (en) Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

29 Jul 2025, 14:14

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 17:15

Updated : 2026-02-25 21:16


NVD link : CVE-2025-29629

Mitre link : CVE-2025-29629

CVE.ORG link : CVE-2025-29629


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor