Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gardyn-hack — CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631 | Kitploit
Tools/GitHubGitHub/kristof-mattei/gardyn-hack
Embedded Systems SecurityPrivilege EscalationIoT SecurityPersistence MechanismsVulnerability AnalysisExploitationLateral MovementPenetration TestingCommand and ControlHardware SecurityRed Teaming
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
kristof-mattei/gardyn-hack

gardyn-hack

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

View Repository

Summary

In February 2025 I conducted security research on a Gardyn Home 4.0 device. During my research, I discovered multiple vulnerabilities and poor security practices. By leveraging these vulnerabilities an attacker may be able to gain system level access to a Gardyn device and use it to stage further attacks against the local area network it is connected to. An attacker may also use this access to affect the normal operation of the device, including damaging the plants being grown in the device and the device itself.

This repository contains the technical details and status for a collection of vulnerabilities in the Gardyn hydroponics garden. This information is being released with the purpose if informing consumers with unresolved issues in the security of the Gardyn product.

Disclosure Timeline

2025-02-21 - Initial contact with vendor attempted. 2025-02-26 - Contact made with vendor sales team. 2025-04-07 - Contact made with vendor technical representative. Technical details of all vulnerabilities disclosed. 2025-06-14 - Follow up attempted with vendor regarding existing vulnerabilties.

as of 2025-07-04

CVEIssueStatus
CVE-2025-29629Weak Default CredentialsThe credentials are still the same, but password authentication has been disabled for SSH
CVE-2025-29630SSH Key BackdoorAn SSH authorized key still exists but has been scrubbed of personally identifying information of a Gardyn Employee.
CVE-2025-29628Full device takeoverUnpatched
CVE-2025-29631Command InjectionUnpatched
Download Tool