Tuya develops a portfolio of IoT and smart-home connectivity platforms and SDKs—including its core Tuya platform, SmartLife applications, and Arduino integration—that span embedded devices, mobile applications, and cloud services. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across weakness classes including cross-site request forgery, execution with unnecessary privileges, buffer overflows, NULL-pointer dereferences, and off-by-one errors that reflect both application-layer and native-code complexity. Defenders should monitor this vendor's advisories given the breadth of connected devices and cloud dependencies in the IoT ecosystem; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tuya over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56400HIGH Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as | Nov 24, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-56557CRITICAL An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol. | Sep 16, 2025 | 9.1 | 30 | NO | NO |
CVE-2026-28519HIGH arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LA | Mar 15, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-28520HIGH arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-cont | Mar 15, 2026 | 8.4 | 28 | NO | NO |
CVE-2026-28521HIGH arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can i | Mar 15, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-28522MEDIUM arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume | Mar 16, 2026 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tuya.
Media articles that mention a CVE ID that affects a product developed by Tuya — matched by CVE ID, not by vendor name.