Skip to main content
Disclosures

Tuya · arduino-TuyaOpen

WiFiUDP Null Pointer Dereference via Malicious Packets

6.5medium
SecMateSECMATE-2026-0003
VendorTuya
Productarduino-TuyaOpen
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
Reported
Feb 22, 2026
Acknowledged
Feb 25, 2026
Fixed
Feb 25, 2026
Published
Mar 12, 2026
Summary

A null pointer dereference vulnerability exists in the WiFiUDP component of arduino-TuyaOpen versions prior to v1.2.1. An attacker on the same local area network (LAN) can continuously send a large number of malicious packets to a device with the WiFiUDP service enabled, causing memory exhaustion and ultimately leading to denial of service.

What's hidden in yours?

Find out