CVE-2025-56400
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-24

Last updated on: 2025-12-30

Assigner: MITRE

Description
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-24
Last Modified
2025-12-30
Generated
2026-05-07
AI Q&A
2025-11-24
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 6 associated CPEs
Vendor Product Version / Range
tuya smartlife 6.3.1
tuya smartlife 6.3.4
tuya tuya to 6.5.0 (exc)
tuya tuya to 6.5.0 (exc)
tuya tuya_smart 6.3.1
tuya tuya_smart 6.3.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the OAuth implementation of the Tuya SDK 6.5.0 used in Tuya Smart and Smartlife mobile apps and other third-party apps integrating the SDK. The apps do not properly validate the OAuth state parameter during account linking, allowing an attacker to trick a victim into clicking a crafted authorization link. This lets the attacker link their own Amazon Alexa account to the victim's Tuya account without the victim's consent.


How can this vulnerability impact me? :

An attacker exploiting this vulnerability can gain unauthorized access to the victim's Tuya-connected devices via their own Alexa account. This could allow remote control of devices such as cameras, doorbells, door locks, or alarms, potentially compromising the victim's security and privacy.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart