CVE-2026-54477 Details
Description
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
A vulnerability exists in the Gardyn IoT Hub admin panel due to the absence of standard security headers. This oversight opens the door to clickjacking and cross-site scripting (XSS) attacks. The issue affects all versions of the Gardyn IoT Hub Home and Studio firmware, as well as the Cloud API versions prior to 2.12.2026.
Gardyn has deployed updates to fix this vulnerability. Users should ensure their devices are connected to the Internet to receive the update automatically. For the Gardyn Home Kit, the firmware version should be 619 or later, and the Gardyn mobile app should be version 2.11.0 or later. Further information can be found on the Gardyn security webpage, and customer support is available via email.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 3, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json | [email protected] | AdvisoryBundleRemedy |
| https://mygardyn.com/security/ | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-644 | Improper Neutralization of HTTP Headers for Scripting Syntax | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Gardyn Home | All versions |
CPE
Remediation
| |
| Gardyn Studio | All versions |
CPE
Remediation
| |
| Gardyn Cloud API | < 2.12.2026 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2026 | New CVE Received | [email protected] |
Volerion