CVE-2025-56400 Details
Description
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the OAuth implementation of the Tuya SDK version 6.5.0 for Android and iOS. This vulnerability affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK. The issue arises because the applications do not properly validate the OAuth state parameter during the account linking process. As a result, an attacker can exploit this flaw by tricking a victim into clicking a crafted authorization link, which would then link the attacker's Amazon Alexa account to the victim's Tuya account. This exploitation allows unauthorized access to the victim's Tuya-connected devices, such as cameras, doorbells, door locks, or alarms.
Users are advised to update the Tuya application to version 6.5.0 or above. Developers should also ensure that their applications are using the latest version of the Tuya SDK.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://src.tuya.com/announcement/30 | [email protected] | Vendor Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| tuya smartlife | 6.3.1 6.3.4 |
CPE
Remediation
| |
| tuya tuya | < 6.5.0 |
CPE
Remediation
| |
| tuya tuya smart | 6.3.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | Initial Analysis | [email protected] |
| Nov 24, 2025 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | New CVE Received | [email protected] |