CVE-2025-29631Patch

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-27); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-25: 1Mentions · 2026-02-27: 3Mentions · 2026-03-02: 1Active Exploitation · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-02: 102-2502-2703-02
Signal classification3 categories
Patch
240.0%
Disclosure
240.0%
General
120.0%
Referenced assets36 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-02-273
Disclosure2Patch1
2026-03-021
General1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    CISA warns of critical flaws (CVE-2025-29631) in Gardyn Home Kits allowing unauthenticated RCE and admin access. Update your app and firmware immediately! #Gardyn #IoT #CyberSecurity #SmartHome #CISA #Vulnerability #InfoSec #GardeningTech #PatchNow https://securityonline.info/rooting-out-risk-cisa-warns-of-critical-9-1-severity-flaws-in-gardyn-smart-gardening-systems/

    Post summary

    CISA warns of unauthenticated remote code execution in Gardyn Home Kits, urging users to update firmware and app immediately.

    10011186
    10.4K followersView on X
  • Machina Record@MachinaRecord
    General

    【リンク集:2月27日〜3月2日のセキュリティ関連ニュース/記事】 <脆弱性> ・Lovableがホストするアプリに多数の基本的な欠陥、ユーザー1万8,000人以上のデータが流出 https://www.theregister.com/2026/02/27/lovable_app_vulnerabilities/ ・OpenClawの脆弱性ClawJacked、Webサイトを介したAIエージェント乗っ取りが可能に(CVE-2026-25253) https://hackread.com/openclaw-vulnerability-openclaw-hijack-ai-agents/ ・Gardyn Smart Gardensに深刻な脆弱性 リモートハッキングにつながる恐れ(CVE-2025-29631、CVE-2025-1242他) https://www.securityweek.com/critical-flaws-exposed-gardyn-smart-gardens-to-remote-hacking/ ・DuckDuckGoブラウザに脆弱性 Autoconsent JS Bridgeを介したユニバーサルXSS https://medium.com/@dhiraj_mishra/duckduckgo-browser-uxss-via-autoconsent-js-bridge-02e3bc27a430 ・Sangoma FreePBXインスタンス900件がWebシェルに感染(CVE-2025-64328) https://www.securityweek.com/900-sangoma-freepbx-instances-infected-with-web-shells/ <マルウェア・その他脅威> ・トロイの木馬化されたゲームツールがJavaベースのRATを拡散 ブラウザやチャットプラットフォームが媒介に https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html ・米CISA、Ivanti製デバイスへの侵入で使われるRESURGEインプラントについて警告(CVE-2025-0282) https://www.bleepingcomputer.com/news/security/cisa-warns-that-resurge-malware-can-be-dormant-on-ivanti-devices/ ・Steaelite RAT:データ窃取とランサムウェアの機能をまとめた有害ツール https://www.theregister.com/2026/02/27/double_extortion_whammy_steaelite_rat/ ・拡張機能「QuickLens」が暗号資産を窃取 ClickFix攻撃も実行 https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/ <データ侵害/サイバー犯罪/その他インシデント> ・韓国国税庁がシードフレーズを誤って公開、480万ドル相当の暗号資産が盗まれる https://www.bleepingcomputer.com/news/security/48m-in-crypto-stolen-after-korean-tax-agency-exposes-wallet-seed/ ・OpenAI、予測市場で機密情報を使用したとして従業員を解雇 https://techcrunch.com/2026/02/27/openai-fires-employee-for-using-confidential-info-on-prediction-markets/ <AI関連> ・OpenAI、米国防総省との「技術的保障措置」に関する合意を発表 https://techcrunch.com/2026/02/28/openais-sam-altman-announces-pentagon-deal-with-technical-safeguards/ ・AnthropicのClaude、米国防総省との対立経てApp Storeで1位に https://techcrunch.com/2026/03/01/anthropics-claude-rises-to-no-2-in-the-app-store-following-pentagon-dispute/ ・セキュリティを考慮した小型版OpenClaw「NanoClaw」が開発される https://www.theregister.com/2026/03/01/nanoclaw_container_openclaw/ ・Anthropic、米国防総省のAIガードレール緩和要求に屈せず 期限迫る https://www.securityweek.com/anthropic-refuses-to-bend-to-pentagon-on-ai-safeguards-as-dispute-nears-deadline/ <サイバー戦/APT/国家型アクター/地政学関連> ・AWS中東のデータセンターに「物体が衝突」 イラン戦争の最中に https://www.theregister.com/2026/03/01/asia_tech_news_roundup/ ・イランのインターネットがほぼ完全に遮断される 米とイスラエルの攻撃下で https://securityaffairs.com/188648/cyber-warfare-2/iran-s-internet-near-totally-blacked-out-amid-us-israeli-strikes.html ・イランのサイバー活動の展望 SentinelOneが分析 https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ユーロポール、ランサムウェア攻撃や恐喝に関与したThe Comのネットワークを摘発 https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/ ・AI活用した偽造IDサイト運営、ウクライナ籍の男が有罪認める https://www.bleepingcomputer.com/news/security/ukrainian-man-pleads-guilty-to-running-ai-powered-fake-id-site/ ・チリ国籍のカーディングショップ運営者、サイバー詐欺関与の疑いで米国に身柄が引き渡される https://www.securityweek.com/chilean-carding-shop-operator-extradited-to-us/ ・米司法省、ロマンス詐欺に関連する6,100万ドル分のテザーコインを押収 https://thehackernews.com/2026/02/doj-seizes-61-million-in-tether-linked.html <プライバシー> ・RedditやHacker Newsで使用される偽名と現実の身元、高い精度で一致可能と判明https://threatroad.substack.com/p/researchers-deanonymize-reddit-and <リサーチ/攻撃手法/TTP> ・CarPlayドングルをリバースエンジニアリング Wi-Fiアクセスからroot化まで https://medium.com/@louis-e/from-wi-fi-access-to-root-reverse-engineering-a-50-carplay-dongle-a3fbeeeb0be9 ・カーネルドライバーをGhidra MCPとClaude Codeでリバースエンジニアリングする方法 https://www.credrelay.com/p/cred-relay-issue-2 ・AIを使ったお手軽リバースエンジニアリング https://blog.huli.tw/2026/03/01/en/reverse-engineering-with-ai-ghidra-mcp/ ・TwitchがiOSアプリでサーバーサイドEppoキーを漏洩、製品ロードマップの全容を公開 https://www.buchodi.com/twitch-ships-server-side-eppo-keys-in-its-ios-app-exposing-its-entire-product-roadmap/ ・北朝鮮のアクターScarCruft、Zoho WorkDriveとマルウェア入りUSBメモリを使ってエアギャップネットワークに侵入 https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html ・ランサムウェアの活動は営業時間外に集中 https://www.helpnetsecurity.com/2026/02/27/sophos-identity-driven-breaches-report/ <政府/政策> ・トランプ大統領、Anthropic製品の使用を段階的に廃止するよう全連邦機関に命令 https://www.securityweek.com/trump-orders-all-federal-agencies-to-phase-out-use-of-anthropic-technology/ ・米カリフォルニア州新法案、Linuxを含む全OSのアカウントセットアップ時に年齢確認を義務化 https://www.pcgamer.com/software/operating-systems/a-new-california-law-says-all-operating-systems-including-linux-need-to-have-some-form-of-age-verification-at-account-setup/ ・米CISAが長官代理を交代 職務混乱の1年を経て https://techcrunch.com/2026/02/27/cisa-replaces-acting-director-gottumukkala-after-a-bumbling-year-on-the-job/ ・欧州議会、保護者の同意なき16歳未満のソーシャルメディア利用を禁止する意見書を承認 https://therecord.media/eu-lawmakers-propose-youth-under-16-social-media-parental-consent <その他> ・堅牢で効率的な耐量子HTTPSの構築 https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html

    Post summary

    The list summarizes several recent security incidents, including multiple CVEs with reported exploitation, but provides limited detail on PoC, patches, or mitigation steps.

    00002251
    1.2K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Gardyn Smart Gardens and Gardyn Studio hit by four critical flaws enabling remote hacking, including CVE-2025-29631 command injection for arbitrary OS commands, CISA warns. #IoT https://threatcluster.io/cluster/gardyn-smart-gardens-vulnerabilities-enable-remote-hacking-a4267b4d

    Post summary

    Gardyn Smart Gardens and Gardyn Studio are impacted by four critical flaws, including CVE-2025-29631 which allows arbitrary OS command execution, and CISA has issued a warning.

    0001034
    83 followersView on X
  • 1K@level01K
    Disclosure

    重大な欠陥により、Gardyn Smart Gardensにリモートハッキングの危険 ・自動化されたLED照明、水循環、AI 駆動型モニタリングを使用し屋内で新鮮な野菜、ハーブ、緑葉植物を栽培し、一年中自家栽培ができる ・CVE-2025-29631、CVE-2025-1242、CVE-2025-29628、CVE-2025-29629 https://www.securityweek.com/critical-flaws-exposed-gardyn-smart-gardens-to-remote-hacking/

    Post summary

    The article announces major flaws (CVE-2025-29631, 1242, 29628, 29629) in Gardyn Smart Gardens, highlighting a potential for remote hacking but without providing proof of exploitation, PoC, or remediation steps.

    0001059
    125 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA warns: Critical Gardyn smart garden flaws enabled remote takeover via hardcoded creds + command injection CISA says Gardyn Home/Studio smart hydroponic kits had two critical issues—hardcoded admin credentials (CVE-2025-1242) and OS command injection (CVE-2025-29631)—plus cleartext sensitive-data transmission and default SSH creds, potentially letting unauthenticated internet attackers seize IoT Hub control and run commands across connected devices. Gardyn says patches (app + firmware) are available and found no evidence of in-the-wild exploitation. 🎯 Target: Global/IoT Consumers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/critical-flaws-exposed-gardyn-smart-gardens-to-remote-hacking/

    Post summary

    CISA warns of two critical flaws in Gardyn smart garden devices that enable remote takeover; patches are available and no in‑the‑wild exploitation has been observed.

    0001047
    227 followersView on X

Explore more