Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tuya:arduino-tuyaopen:*:*:*:*:*:*:*:* |
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tuya
Tuya arduino-tuyaopen |
|
| Vendors & Products |
Tuya
Tuya arduino-tuyaopen |
Sun, 15 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result in information disclosure or a denial-of-service condition. | |
| Title | arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:20:19.227Z
Reserved: 2026-02-27T21:07:55.466Z
Link: CVE-2026-28521
Updated: 2026-03-16T14:17:35.673Z
Status : Analyzed
Published: 2026-03-16T14:19:28.557
Modified: 2026-03-17T20:24:33.687
Link: CVE-2026-28521
No data.
OpenCVE Enrichment
Updated: 2026-03-23T14:01:42Z