Junglewise Threat Intelligence

CVE-2025-56400: Tuya SDK CSRF in OAuth account linking flow

CVE-2025-56400 · Severity: high · CVSS 8.8 · Published 2025-11-24

Executive brief

A security flaw in the Tuya SDK, used by Tuya Smart, Smartlife, and various third-party smart home apps, allows attackers to gain unauthorized control over a user's connected devices. By tricking a user into clicking a malicious link, an attacker can link their own Amazon Alexa account to the victim's smart home profile. This could allow an unauthorized person to remotely operate sensitive home hardware such as security cameras, smart locks, doorbells, and alarms.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the OAuth implementation of the Tuya SDK (v6.5.0 and earlier) for Android and iOS. The vulnerability stems from a failure to validate the OAuth 'state' parameter during the account linking flow. An attacker can exploit this by tricking a victim into clicking a specially crafted authorization link, which completes the OAuth handshake using the attacker's credentials on the victim's session. This results in the attacker's Amazon Alexa account being linked to the victim's Tuya-managed ecosystem. Successful exploitation grants the attacker remote access to the victim's IoT devices, including cameras and locks, and does not require the Tuya application to be actively running at the time of the attack.

Affected products

  • Tuya Tuya SDK 6.5.0 and earlier
  • Tuya Tuya Smart Before 6.5.0
  • Tuya Smartlife Before 6.5.0

Timeline

  • 2025-11-24: advisory
  • 2025-11-24: disclosed

References

Related threats