CVE-2026-28519 is a high-severity heap-based buffer overflow vulnerability found in the DnsServer component of arduino-TuyaOpen before version 1.2.1, affecting embedded devices utilizing this library. With a CVSS score of 8.8 (High), an attacker on the same local area network can exploit this by controlling the LAN DNS server and sending malicious DNS responses, potentially leading to arbitrary code execution. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB) or evidence of active exploitation in the KEV catalog, the vulnerability is marked as "Hot List: Active" and has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.1CPE matchmatch criteria | cpe:2.3:a:tuya:arduino-tuyaopen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.