CVE Feed

    Dashboard / CVE / CVE-2025-29631

    CVE-2025-29631

    Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit.

    Published:Jul 25, 2025
    Last Modified:Apr 15, 2026
    EPS:Jul 25, 2025
    EPSS Score:0.00509
    CVSS Score:9.8

    Affected Products

    No affected product recorded yet

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High