Export limit exceeded: 371441 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-13768 1 Gardyn 3 Gardyn Cloud Api, Gardyn Home Firmware, Gardyn Studio Firmware 2026-07-29 10 Critical
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
CVE-2026-55726 1 Gardyn 3 Gardyn Cloud Api, Gardyn Home Firmware, Gardyn Studio Firmware 2026-07-29 5.3 Medium
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
CVE-2026-54477 1 Gardyn 3 Gardyn Cloud Api, Gardyn Home Firmware, Gardyn Studio Firmware 2026-07-29 5.4 Medium
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.