Cross-Site Request Forgery Vulnerability in Tuya SDK for Mobile Applications
CVE-2025-56400

8.8HIGH

Key Information:

Vendor

Tuya

Status
Vendor
CVE Published:
24 November 2025

What is CVE-2025-56400?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the OAuth implementation of the Tuya SDK 6.5.0, impacting both Android and iOS platforms. This flaw affects the Tuya Smart and Smartlife mobile applications as well as any third-party applications utilizing the SDK. The vulnerability arises from the failure to validate the OAuth state parameter during the account linking process. An attacker can exploit this by misleading a victim into clicking a specially crafted authorization link, allowing the attacker to complete the OAuth flow on behalf of the victim without their consent. As a result, unauthorized access to the victim's Tuya-connected devices, including security cameras and smart locks, may occur. This risk persists irrespective of whether the victim has previously linked their Amazon Alexa account, making it a significant security concern for users.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.