CVE-2026-28520
EUVD-2026-1222716.03.2026, 14:19
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tuya | arduino-tuyaopen | 𝑥 < 1.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration