CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-29628

CVSS 9.4v3.1pub. 2025-07-25upd. 2026-04-15

A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.

🤖 AI Analysis
How it works

The Gardyn Home Kit device firmware, mobile application, and Cloud API retrieve the connection string for Azure IoT Hub using unencrypted HTTP protocol instead of HTTPS. Network traffic transmitted as plaintext can be intercepted by an attacker located on the same network or on the network path between the device and the server (Man-in-the-Middle attack). The attacker can not only read the connection string containing device authentication credentials but also modify it, directing the device to their own infrastructure.

Impact

An attacker can obtain sensitive device authentication credentials (CWE-200) or — by substituting a modified connection string — take control of vulnerable Home Kit devices (CWE-924, CWE-77).

Mitigation & patch

Update firmware to version master.619 or later, mobile application to version 2.11.0 or later, and Cloud API to version 2.12.2026 or later. Detailed information is available in the manufacturer's statement and ICS-CERT advisory ICSA-26-055-03.

Who is affected

Gardyn Home Kit firmware before version master.619, Home Kit Mobile Application before version 2.11.0, and Home Kit Cloud API before version 2.12.2026.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References