CVE-2025-29628 describes a critical vulnerability in Gardyn Home Kit firmware (before master.619), mobile application (before 2.11.0), and Cloud API (before 2.12.2026) where Azure IoT Hub connection strings are downloaded insecurely via HTTP. This allows for Man-in-the-Middle attacks, enabling attackers to intercept or modify credentials and potentially gain control of affected home kits. With a CVSS score of 9.4 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity, posing a high risk to confidentiality, integrity, and a low risk to availability. There is currently no public exploit code available, it is not on the CISA KEV catalog, and community discussion and media coverage are minimal, suggesting limited active exploitation or awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Gardyn | Home Kit Firmware | >= 0, < master.619CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 1.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.