CVE-2025-56557

9.1

Tuya · Smart Life App

The Tuya Smart Life App version 5.6.1 contains a vulnerability allowing unauthenticated attackers to control Matter-enabled devices via the Matter protocol.

Executive summary

An unauthenticated control vulnerability in the Tuya Smart Life App allows unauthorized actors to manipulate Matter-connected smart devices.

Vulnerability

This is an authentication bypass or protocol manipulation issue allowing unprivileged, remote attackers to control Matter devices. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no authentication or user interaction is required to initiate the attack.

Business impact

With a CVSS score of 9.1, this vulnerability is critical as it allows for the unauthorized control of smart devices without any authentication. This could result in the compromise of physical security, privacy, or home/facility automation, presenting both reputational and operational risks to users relying on Tuya-integrated ecosystems.

Remediation

Immediate Action: Update the Tuya Smart Life App to the latest available version provided by the vendor. If an update is not available, isolate Matter-enabled devices from the internet where possible.

Proactive Monitoring: Monitor the status of connected smart devices for unexpected behavior, such as unauthorized power cycling, light changes, or modifications to device settings.

Compensating Controls: Implement network-level segmentation to isolate smart home devices from primary business or home networks to limit the impact of a potential breach.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Users are strongly advised to update the Tuya Smart Life App immediately. Given the nature of Matter-protocol vulnerabilities, users should also verify the security settings of their individual smart devices and ensure they are running the latest firmware provided by the device manufacturers.