CVE-2026-28519 PUBLISHED

arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

Assigner: VulnCheck
Reserved: 27.02.2026 Published: 15.03.2026 Updated: 15.03.2026

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary code on affected embedded devices.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Tuya
Product arduino-TuyaOpen
Versions
  • affected from 0 to 1.2.1 (excl.)

Credits

  • Maxime ROSSI BELLOM finder

References

Problem Types

  • Heap-based Buffer Overflow CWE