Skip to main content
Disclosures

Tuya · arduino-TuyaOpen

TuyaIoT Out-of-Bounds Read in DP Event Handling

6.5medium
SecMateSECMATE-2026-0002
VendorTuya
Productarduino-TuyaOpen
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Timeline
Reported
Feb 22, 2026
Acknowledged
Feb 25, 2026
Fixed
Feb 25, 2026
Published
Mar 12, 2026
Summary

A memory out-of-bounds read vulnerability exists in the TuyaIoT DP event handling of arduino-TuyaOpen versions prior to v1.2.1. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to a connected device, causing out-of-bounds memory access that may lead to denial of service.

What's hidden in yours?

Find out