Gardyn Home Kit and Studio Remote User Profile Pivot Vulnerability

Vulnerability

A vulnerability exists in the Gardyn Home Kit and Gardyn Studio ecosystems, specifically within the Gardyn Cloud API. The issue allows authenticated users to access other user profiles by altering the ID number in the API call. This vulnerability could lead to unauthorized access to personal information and cloud-based devices managed within the Gardyn environment.

Impact

Exploitation of this vulnerability could allow authenticated users to access and control other users' edge devices, cloud-based devices, and personal information, including limited data such as names, addresses, phone numbers, and email addresses.

Remediation

Users are advised to update their Gardyn mobile application to version 2.11.0 or later and ensure their Gardyn Home Kit and Studio devices are upgraded to firmware version master.622 or later. Further information on Gardyn security can be found on the Gardyn security webpage, and customer support is available via email at support@mygardyn.com.

Added: Apr 3, 2026, 9:26 PM
Updated: Apr 3, 2026, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
5.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.