VYPR
Vendor

Tuya

Products
7
CVEs
10
Across products
16
Status
Private

Products

7

Recent CVEs

10
  • CVE-2025-56557CriSep 16, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.

  • CVE-2025-56400HigNov 24, 2025
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own…

  • CVE-2025-5748HigJun 6, 2025
    risk 0.52cvss 8.0epss 0.00

    WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger. Although authentication is required to exploit…

  • CVE-2026-28519HigMar 16, 2026
    risk 0.50cvss 8.8epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing…

  • CVE-2026-28520HigMar 16, 2026
    risk 0.48cvss 8.4epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected…

  • CVE-2026-28521HigMar 16, 2026
    risk 0.43cvss 7.7epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result…

  • CVE-2026-28522MedMar 16, 2026
    risk 0.35cvss 6.5epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets that trigger a null pointer dereference, resulting in a denial-of-service…

  • CVE-2024-32268LowApr 29, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.

  • CVE-2026-3465LowMar 3, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack…

  • CVE-2024-3764LowApr 14, 2024
    risk 0.18cvss 2.7epss 0.01

    ** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been…