CVE-2026-28520
Awaiting Analysis
Awaiting Analysis - Queue
Single-Byte Buffer Overflow in Arduino-TuyaOpen WiFiMulti Enables RCE
Publication date: 2026-03-16
Last updated on: 2026-03-17
Assigner: VulnCheck
Description
Description
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tuya | arduino-tuyaopen | to 1.2.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-193 | A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value. |