Ad

CVE-2025-56400

HIGH CVSS 3.1: 8.8 EPSS 0.02%
Updated Dec 30, 2025
Tuya
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions before 6.5.0
Fixed In 6.5.0
Type CWE-384, CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Tuya
Public PoC No

Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices.

This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 6

Configuration From (including) Up to (excluding)
Tuya Smartlife
cpe:2.3:a:tuya:smartlife:6.3.1:*:*:*:*:iphone_os:*:*
Tuya Smartlife
cpe:2.3:a:tuya:smartlife:6.3.4:*:*:*:*:android:*:*
Tuya Tuya
cpe:2.3:a:tuya:tuya:*:*:*:*:*:android:*:*
6.5.0
Tuya Tuya
cpe:2.3:a:tuya:tuya:*:*:*:*:*:iphone_os:*:*
6.5.0
Tuya Tuya_Smart
cpe:2.3:a:tuya:tuya_smart:6.3.1:*:*:*:*:android:*:*
Tuya Tuya_Smart
cpe:2.3:a:tuya:tuya_smart:6.3.1:*:*:*:*:iphone_os:*:*