<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:10:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-270723</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270723</link>
      <description>EUVD-2026-270723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270723</guid>
    </item>
    <item>
      <title>fkie_cve-2025-29628</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-29628</link>
      <description>&lt;p&gt;A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-29628</guid>
    </item>
    <item>
      <title>GHSA-82xm-jwxq-4436</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-82xm-jwxq-4436</link>
      <description>&lt;p&gt;An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-82xm-jwxq-4436</guid>
    </item>
    <item>
      <title>ICSA-26-055-03 — Gardyn Home Kit (Update B)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-055-03</link>
      <description>&lt;p&gt;A Gardyn Azure IoT Hub connection string  is downloaded over an insecure HTTP connection leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits. The Gardyn Home Kit uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. The Gardyn Home Kit is vulnerable to command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit. The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining  full administrative access to the Gardyn IoT Hub exposing connected devices to malicious control. Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers. A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. A specific endpoint allows authenticated users to pivot to other user profile…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Gardyn Azure IoT Hub connection string  is downloaded over an insecure HTTP connection leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits. The Gardyn Home Kit uses weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. The Gardyn Home Kit is vulnerable to command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit. The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining  full administrative access to the Gardyn IoT Hub exposing connected devices to malicious control. Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers. A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. A specific endpoint allows authenticated users to pivot to other user profile…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-055-03</guid>
    </item>
  </channel>
</rss>
