CVE-2025-29628
An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- EPSS probability
- 0.27%
- CWE
- CWE-924
- Published
- 2025-07-25
- Last modified
- 2026-03-13
Affected products
- Gardyn Home Kit Firmware
Weakness type
Related vulnerabilities
- CVE-2026-48106 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-68554 — Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
- CVE-2026-14681 — PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
- CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
- CVE-2026-54891 — Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
- CVE-2026-12576 — DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
- CVE-2019-25719 — Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
- CVE-2025-0592 — SICK Lector8xx and InspectorP8xx vulnerable for code execution