CVE-2025-56557: Critical severity Tuya Smart Life App vulnerability
Published Sep 16, 2025
·Updated
An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.
Affected Software
2 affected components
Tuya Smart Life App
Tuya Tuya=5.6.1
Event History
Sep 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56557?
CVE-2025-56557 is considered a critical vulnerability due to the potential for unprivileged control of Matter devices.
2
How do I fix CVE-2025-56557?
To mitigate CVE-2025-56557, users should update the Tuya Smart Life App to the latest version provided by the vendor.
3
What devices are affected by CVE-2025-56557?
CVE-2025-56557 affects Matter devices controlled via the Tuya Smart Life App version 5.6.1.
4
Can CVE-2025-56557 be exploited remotely?
Yes, CVE-2025-56557 can be exploited remotely, allowing attackers to gain control over devices without authentication.
5
Is there a patch available for CVE-2025-56557?
A patch for CVE-2025-56557 is typically released in the latest updates of the Tuya Smart Life App, so users should check for updates regularly.