CVE-2026-28522: Tuya Arduino-Tuyaopen

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets that trigger a null pointer dereference, resulting in a denial-of-service condition.

Affected products

  • Tuya Arduino-Tuyaopen: before 1.2.1 (fixed in 1.2.1)

Published 2026-03-16. Last modified 2026-06-17.