Executive brief
A vulnerability exists in the Tuya Arduino core, which is used to develop software for smart IoT devices. An attacker on the same local network can send a flood of malicious data packets to crash the device, causing it to become unresponsive. This could disrupt the operation of smart home or industrial equipment and require a manual restart to restore service.
Technical details
A null pointer dereference vulnerability exists in the WiFiUDP component of arduino-TuyaOpen prior to version 1.2.1. The flaw is triggered when the device receives a large volume of malicious UDP packets, which leads to memory exhaustion. This exhaustion subsequently causes a null pointer dereference, resulting in a system crash or denial-of-service (DoS). The attack is network-based but requires the attacker to be on the same local area network (adjacent) as the target device. No authentication or user interaction is required to exploit this vulnerability. Users should update to version 1.2.1 or later to remediate the issue.
Affected products
- Tuya arduino-TuyaOpen < 1.2.1
Timeline
- 2026-03-15: advisory: Initial advisory published by VulnCheck
- 2026-03-16: disclosed: CVE published to NVD