Gardyn IoT Hub
This advisory details a vulnerability within the Gardyn IoT Hub, specifically versions prior to 2.12.2026, that allows unauthenticated users to potentially gain control of connected devices. The vulnerability stems from a hard-coded privileged key exposing connection information and enabling arbitrary command execution. Furthermore, the system suffers from insecure admin panel configurations, increasing the risk of clickjacking and cross-site scripting attacks, alongside publicly accessible device logs.
The CISA advisory highlights a critical vulnerability affecting Gardyn IoT Hub devices. The core issue revolves around a hard-coded privileged key within the Cloud API, allowing unauthorized access to device connection information and the ability to execute commands on connected devices. This could enable attackers to pivot within the user's network and potentially compromise other devices. Additionally, the advisory notes a lack of standard security headers in the admin panel, creating an avenue for clickjacking and cross-site scripting attacks. Finally, the Azure Blob Storage container used for Gardyn device logs is publicly accessible without authentication, exposing device log data to unauthorized access.