A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.
The Gardyn Home Kit device firmware, mobile application, and Cloud API retrieve the connection string for Azure IoT Hub using unencrypted HTTP protocol instead of HTTPS. Network traffic transmitted as plaintext can be intercepted by an attacker located on the same network or on the network path between the device and the server (Man-in-the-Middle attack). The attacker can not only read the connection string containing device authentication credentials but also modify it, directing the device to their own infrastructure.
An attacker can obtain sensitive device authentication credentials (CWE-200) or — by substituting a modified connection string — take control of vulnerable Home Kit devices (CWE-924, CWE-77).
Update firmware to version master.619 or later, mobile application to version 2.11.0 or later, and Cloud API to version 2.12.2026 or later. Detailed information is available in the manufacturer's statement and ICS-CERT advisory ICSA-26-055-03.
Gardyn Home Kit firmware before version master.619, Home Kit Mobile Application before version 2.11.0, and Home Kit Cloud API before version 2.12.2026.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L