Executive brief
Gardyn Cloud API, which manages smart home hydroponic gardening systems, contained active development and test endpoints. These endpoints mirrored production functionality and could allow unauthorized individuals to access sensitive information such as plant photos or limited user demographic data. The manufacturer has released updates to the Cloud API and mobile application to remove these exposed interfaces.
Technical details
The Gardyn Cloud API, used for managing Gardyn Home and Studio devices, was found to have active debug code (CWE-489) in the form of development and test API endpoints. These endpoints remained accessible in the production environment and mirrored the functionality of production APIs. An unauthenticated remote attacker could leverage these endpoints to access sensitive information, including plant photos and limited demographic data (names, addresses, phone numbers, and email addresses). The vulnerability is addressed in Gardyn Cloud API versions 2.12.2026 and later.
Affected products
- Gardyn Cloud API before 2.12.2026
Timeline
- 2026-02-24: patched: Original vendor remediation date
- 2026-04-03: disclosed: Initial NVD publication
- 2026-04-03: advisory: ICS-CERT advisory published