According to the April 2026 advisory update, the vulnerabilities carry a high CVSS score of 9.3, indicating severe risk.
Successful exploitation could enable unauthenticated attackers to fully compromise edge devices and gain access to sensitive user data stored in the Gardyn cloud environment.
Security researcher Michael Groberman initially identified and reported the vulnerabilities, which have now been formally documented by CISA in Update A of its advisory.
The advisory expands on an earlier February release and introduces several newly tracked CVEs, including:
These flaws impact multiple components of the Gardyn ecosystem:
The vulnerabilities stem from fundamental security weaknesses in authentication, authorization, and data handling mechanisms.
Key technical issues include:
These combined flaws create a dangerous attack surface, allowing threat actors to compromise devices without prior authentication.
CISA warns that a compromised Gardyn device could serve as an entry point into broader networks.
Attackers may use the infected system to pivot into the Gardyn cloud infrastructure or other connected devices on the same network.
This significantly increases the risk, especially in environments where smart devices are integrated into larger home or enterprise networks.
Despite the severity, CISA has stated that there is currently no evidence of active exploitation in the wild.
CISA urges users and organizations to take immediate action to reduce exposure.
Recommended measures include:
Users are also advised to conduct risk assessments before implementing changes to prevent operational disruptions.
Any signs of compromise or suspicious behavior should be reported promptly, and incident response procedures should be initiated immediately.
As smart agriculture and IoT devices continue to expand, this advisory highlights the growing importance of securing connected systems against evolving cyber threats.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Critical Gardyn Smart Gardens Vulnerabilities Let Attackers Control Devices Remotely appeared first on Cyber Security News.
The Sonos Earth Day Sale runs now through March 24, and in the spirit of…
Ubisoft has confirmed when it will officially unveil Assassin's Creed Black Flag Resynced, via a…
Why not just get a complete, warrantied prebuilt system that also includes DDR5 memory for…
Pre-orders for Pokémon TCG: Chaos Rising are starting to bubble, following the official announcement of…
Roku City is a true landmark of the streaming era, and the company behind the…
Artificial intelligence is reshaping recruitment far beyond chatbots and resume parsing. For Adam Godson, former…
This website uses cookies.