arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary code on affected embedded devices.
References
| Link | Resource |
|---|---|
| https://github.com/tuya/arduino-TuyaOpen | Product |
| https://src.tuya.com/announcement/32 | Vendor Advisory |
| https://www.vulncheck.com/advisories/arduino-tuyaopen-dnsserver-heap-based-buffer-overflow-remote-code-execution | Third Party Advisory |
Configurations
History
17 Mar 2026, 15:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:tuya:arduino-tuyaopen:*:*:*:*:*:*:*:* | |
| First Time |
Tuya
Tuya arduino-tuyaopen |
|
| References | () https://github.com/tuya/arduino-TuyaOpen - Product | |
| References | () https://src.tuya.com/announcement/32 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/arduino-tuyaopen-dnsserver-heap-based-buffer-overflow-remote-code-execution - Third Party Advisory |
16 Mar 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:19
Updated : 2026-03-17 15:38
NVD link : CVE-2026-28519
Mitre link : CVE-2026-28519
CVE.ORG link : CVE-2026-28519
JSON object : View
Products Affected
tuya
- arduino-tuyaopen
CWE
CWE-122
Heap-based Buffer Overflow
