CVE 8.8 HIGH

Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials_CVE-2025-10681

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

Description

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers.

Basic Information

ID CVE-2025-10681
Source icscert
Published Apr 3, 2026 at 20:26
Modified Apr 6, 2026 at 14:39

Affected Product

Vendor Gardyn
Product Mobile Application
Affected Versions Gardyn Mobile Application 0
Gardyn Cloud API 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.