
CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631
In February 2025 I conducted security research on a Gardyn Home 4.0 device. During my research, I discovered multiple vulnerabilities and poor security practices. By leveraging these vulnerabilities an attacker may be able to gain system level access to a Gardyn device and use it to stage further attacks against the local area network it is connected to. An attacker may also use this access to affect the normal operation of the device, including damaging the plants being grown in the device and the device itself.
This repository contains the technical details and status for a collection of vulnerabilities in the Gardyn hydroponics garden. This information is being released with the purpose if informing consumers with unresolved issues in the security of the Gardyn product.
2025-02-21 - Initial contact with vendor attempted. 2025-02-26 - Contact made with vendor sales team. 2025-04-07 - Contact made with vendor technical representative. Technical details of all vulnerabilities disclosed. 2025-06-14 - Follow up attempted with vendor regarding existing vulnerabilties.
as of 2025-07-04
| CVE | Issue | Status |
|---|---|---|
| CVE-2025-29629 | Weak Default Credentials | The credentials are still the same, but password authentication has been disabled for SSH |
| CVE-2025-29630 | SSH Key Backdoor | An SSH authorized key still exists but has been scrubbed of personally identifying information of a Gardyn Employee. |
| CVE-2025-29628 | Full device takeover | Unpatched |
| CVE-2025-29631 | Command Injection | Unpatched |