6.5medium
SecMateSECMATE-2026-0002
VendorTuya
Productarduino-TuyaOpen
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Timeline
Reported
Feb 22, 2026
Acknowledged
Feb 25, 2026
Fixed
Feb 25, 2026
Published
Mar 12, 2026
Summary
A memory out-of-bounds read vulnerability exists in the TuyaIoT DP event handling of arduino-TuyaOpen versions prior to v1.2.1. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to a connected device, causing out-of-bounds memory access that may lead to denial of service.