Vulnerability Intelligence Report
CVE-2025-29629
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1392 ↗CWE-1392 Use of Default Credentials
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Gardyn | Home Kit Firmware | 0 < master.619 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.464%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2025-03-11T00:00:00 |
| Published | 2025-07-25T00:00:00 |
| Last Updated | 2026-02-25T20:42:11 |
Community Chatter & Buzz