Description

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected devices to malicious control.

INFO

Published Date :

2026-02-25T15:21:48.369Z

Last Modified :

2026-04-22T17:54:24.634Z

Source :

icscert
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1242 vulnerability.

Vendors Products
Gardyn
  • Home Kit
  • Home Kit Cloud Api
  • Home Kit Mobile Application
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact