ICSA-26-055-03
·
Published 2026-07-02
·
View on CISA ICS-CERT ↗
Gardyn Home Kit (Update B)
CVSS 9.3
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control edge devices, access cloud-based devices and user information without authentication, and pivot to other edge devices managed in the Gardyn cloud environment.
CVEs (10)
Remediations
- Gardyn states that the relevant fixes are included in the latest version of the Gardyn mobile application. Users are required to run a supported version of the Gardyn App on their phone in order to access Gardyn services and devices.
- The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.
- Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version.
- Further information on Gardyn security can be found here: https://mygardyn.com/security/
- Further customer support can be obtained from Gardyn at: [email protected]
Affected Vendors
Gardyn
Affected Products (4)
Gardyn
·
Gardyn Home Firmware
<master.622
Gardyn
·
Gardyn Studio Firmware
<master.622
Gardyn
·
Gardyn Mobile Application
<2.11.0
Gardyn
·
Gardyn Cloud API
<2.12.2026
Affected Sectors
Food and Agriculture
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more