Cross-Site Request Forgery Vulnerability in Tuya SDK for Mobile Applications
CVE-2025-56400
What is CVE-2025-56400?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the OAuth implementation of the Tuya SDK 6.5.0, impacting both Android and iOS platforms. This flaw affects the Tuya Smart and Smartlife mobile applications as well as any third-party applications utilizing the SDK. The vulnerability arises from the failure to validate the OAuth state parameter during the account linking process. An attacker can exploit this by misleading a victim into clicking a specially crafted authorization link, allowing the attacker to complete the OAuth flow on behalf of the victim without their consent. As a result, unauthorized access to the victim's Tuya-connected devices, including security cameras and smart locks, may occur. This risk persists irrespective of whether the victim has previously linked their Amazon Alexa account, making it a significant security concern for users.
