VYPR
Unrated severityNVD Advisory· Published Mar 15, 2026· Updated Mar 16, 2026

arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

CVE-2026-28522

Description

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets to cause memory exhaustion on the device, triggering a null pointer dereference and resulting in a denial-of-service condition.

Affected products

1
  • Tuya/arduino-TuyaOpenv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.