CVE-2026-28522: arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service
Published Mar 15, 2026
·Updated
arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets that trigger a null pointer dereference, resulting in a denial-of-service condition.
Affected Software
2 affected components
arduino/arduino-TuyaOpen<1.2.1
Tuya arduino-TuyaOpen<1.2.1
Event History
Mar 15, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Mar 16, 2026
Data Sourced
via NVD·02:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28522?
CVE-2026-28522 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2026-28522?
To mitigate CVE-2026-28522, upgrade arduino-TuyaOpen to version 1.2.1 or later.
3
Who is affected by CVE-2026-28522?
CVE-2026-28522 affects users of arduino-TuyaOpen before version 1.2.1.
4
What causes CVE-2026-28522?
CVE-2026-28522 is caused by a null pointer dereference in the WiFiUDP component.
5
Can CVE-2026-28522 be exploited remotely?
CVE-2026-28522 can be exploited by an attacker on the same local area network.