CVE-2026-28520: arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28520?
CVE-2026-28520 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-28520?
The recommended fix for CVE-2026-28520 is to upgrade to arduino-TuyaOpen version 1.2.1 or later.
What does CVE-2026-28520 exploit?
CVE-2026-28520 exploits a buffer overflow vulnerability in the WiFiMulti component when connecting to an attacker-controlled WiFi access point.
Who is affected by CVE-2026-28520?
CVE-2026-28520 affects users of arduino-TuyaOpen versions prior to 1.2.1.
What are the consequences of CVE-2026-28520 if unpatched?
If unpatched, CVE-2026-28520 can lead to remote code execution on vulnerable devices when they connect to malicious networks.