CVE-2025-1242: Gardyn Home Kit

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected devices to malicious control.

Affected products

  • Gardyn Home Kit
  • Gardyn Home Kit Cloud API: before 2.12.2026 (fixed in 2.12.2026)
  • Gardyn Home Kit Mobile Application: before 2.11.0 (fixed in 2.11.0)

Published 2026-02-25. Last modified 2026-06-17.