CVE-2025-56400
8.8Tuya · SDK 6 (Tuya Smart and Smartlife applications)
A CSRF vulnerability in the Tuya SDK 6.5.0 OAuth implementation allows unauthenticated attackers to link unauthorized Amazon Alexa accounts to victim devices, enabling remote control of smart hardware.
Executive summary
A critical CSRF vulnerability in Tuya SDK 6.5.0 allows unauthorized third-party account linking, potentially granting attackers remote control over connected smart home devices.
Vulnerability
The vulnerability exists due to a failure to validate the OAuth state parameter during the account linking flow, which allows an unauthenticated attacker to manipulate the authentication process. By inducing a user to interact with a crafted link, the attacker can force the victim to associate an attacker-controlled Alexa account with their Tuya ecosystem.
Business impact
The potential for unauthorized remote control of security-sensitive devices, such as door locks, cameras, and alarm systems, represents a severe physical and digital safety risk. With a CVSS score of 8.8, this flaw poses a high risk to user privacy and home security. Successful exploitation could lead to unauthorized surveillance, physical entry, or the disruption of critical home automation services.
Remediation
Immediate Action: Users and developers should update to the latest available version of the Tuya SDK or the affected applications as provided by the vendor. Consult the official Tuya security announcement at https://src.tuya.com/announcement/30 for specific patch availability.
Proactive Monitoring: Security teams should monitor for unusual OAuth account linking activities or unexpected third-party service connections within account management logs.
Compensating Controls: While difficult to mitigate via network controls, users should exercise extreme caution when interacting with unsolicited links or suspicious authorization prompts during account management flows.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for physical security compromise, this vulnerability should be treated with high priority. Organizations utilizing the Tuya SDK must verify their current version and apply vendor-provided updates immediately upon release. If an update is not currently available, users should review their connected account settings for any unauthorized third-party integrations and remove them immediately.