CVE-2025-10681: Gardyn Cloud API

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers.

Affected products

  • Gardyn Cloud API: before 2.12.2026 (fixed in 2.12.2026)
  • Gardyn Mobile Application: before 2.11.0 (fixed in 2.11.0)

Published 2026-04-03. Last modified 2026-07-24.