CVE-2026-28519

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary code on affected embedded devices.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tuya:arduino-tuyaopen:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:28

Type Values Removed Values Added
Summary
  • (es) arduino-TuyaOpen antes de la versión 1.2.1 contiene una vulnerabilidad de desbordamiento de búfer basado en montículo en el componente DnsServer. Un atacante en la misma red de área local que controla el servidor DNS de la LAN puede enviar respuestas DNS maliciosas para desbordar el búfer del montículo, lo que podría permitir la ejecución de código arbitrario en los dispositivos embebidos afectados.

17 Mar 2026, 15:38

Type Values Removed Values Added
References () https://github.com/tuya/arduino-TuyaOpen - () https://github.com/tuya/arduino-TuyaOpen - Product
References () https://src.tuya.com/announcement/32 - () https://src.tuya.com/announcement/32 - Vendor Advisory
References () https://www.vulncheck.com/advisories/arduino-tuyaopen-dnsserver-heap-based-buffer-overflow-remote-code-execution - () https://www.vulncheck.com/advisories/arduino-tuyaopen-dnsserver-heap-based-buffer-overflow-remote-code-execution - Third Party Advisory
CPE cpe:2.3:a:tuya:arduino-tuyaopen:*:*:*:*:*:*:*:*
First Time Tuya
Tuya arduino-tuyaopen

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-06-17 10:28


NVD link : CVE-2026-28519

Mitre link : CVE-2026-28519

CVE.ORG link : CVE-2026-28519


JSON object : View

Products Affected

tuya

  • arduino-tuyaopen
CWE
CWE-122

Heap-based Buffer Overflow