Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22717 | An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits. |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 25 Feb 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-924 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 25 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-77 |
|
| Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-25T20:14:40.989Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29628
Updated: 2025-07-25T20:22:59.830Z
Status : Awaiting Analysis
Published: 2025-07-25T17:15:31.027
Modified: 2026-02-25T21:16:31.323
Link: CVE-2025-29628
No data.
OpenCVE Enrichment
No data.
EUVD