Executive brief
Gardyn Cloud API, which manages smart home hydroponic gardening systems, contains a security flaw where a specific administrative interface is accessible without a password. An unauthorized person could exploit this to access device management functions, potentially allowing them to view plant photos or access limited customer information like names and addresses. Gardyn has released updates to address this issue and reports no evidence of malicious exploitation.
Technical details
The Gardyn Cloud API (versions prior to 2.12.2026) suffers from a missing authentication vulnerability (CWE-306) in a specific administrative endpoint. This flaw allows a remote, unauthenticated attacker to access sensitive device management functions and retrieve user information, including plant photos and demographic data (name, address, phone number, and email). The vulnerability is reachable over the network without user interaction. Gardyn has remediated the issue in Cloud API version 2.12.2026 and recommends users ensure their mobile app is version 2.11.0 or later and device firmware is version 627 or later.
Affected products
- Gardyn Cloud API < 2.12.2026
Timeline
- 2026-02-24: patched: Original vendor remediation date
- 2026-04-03: disclosed: Initial NVD publication
- 2026-07-02: advisory: Latest revision of CISA ICS advisory