CVE-2026-28522

Publication date

2026-03-15 13:36:52

Family

VulnCheck

State

PUBLISHED

Description

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets to cause memory exhaustion on the device, triggering a null pointer dereference and resulting in a denial-of-service condition.