Executive brief
Gardyn smart indoor gardening systems are affected by a security flaw where storage credentials were permanently embedded in the mobile app and device software. An attacker could use these credentials to gain unauthorized access to the company's cloud storage, potentially exposing customer data such as plant photos and limited contact information. The manufacturer has released updates that fix this issue and rotate the compromised credentials.
Technical details
The vulnerability (CWE-798) involves the use of hardcoded credentials within the Gardyn mobile application and device firmware. These credentials facilitate access to production storage containers (such as Azure IoT Hub or similar cloud storage) but lack adequate permission limiting and do not expire. A remote, unauthenticated attacker can extract these credentials from the application or firmware to gain unauthorized access to cloud-based storage. This could lead to the exposure of user information, including plant photos and demographic data (name, address, phone number). Gardyn has remediated the issue by updating the Mobile App to version 2.11.0, the Cloud API to 2.12.2026, and device firmware to version 627 or later.
Affected products
- Gardyn Mobile Application < 2.11.0
- Gardyn Cloud API < 2.12.2026
- Gardyn Home Firmware < 627
- Gardyn Studio Firmware < 627
Timeline
- 2026-02-24: patched: Original remediation and internal publication by Gardyn
- 2026-04-02: other: Revision of Gardyn security update
- 2026-04-03: advisory: Initial NVD/CISA publication
- 2026-07-02: other: Final revision of CISA advisory