PT-2026-55340 · Gardyn · Gardyn Cloud Api+2

Michael Groberman

·

Published

2026-07-02

·

Updated

2026-07-03

·

CVE-2026-54477

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The admin panel lacks standard security headers, which allows for clickjacking and cross-site scripting attacks. Clickjacking is a technique where a user is tricked into clicking a hidden element, while cross-site scripting involves injecting malicious scripts into web pages viewed by other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54477

Affected Products

Gardyn Cloud Api
Gardyn Home Firmware
Gardyn Studio Firmware