Skip to main content
EPSS 0.2%top 93%

CVE-2025-56400: n/a

0
High
VulnerabilityCVE-2025-56400cvecve-2025-56400
Published: 11/24/2025 (11/24/2025, 00:00:00 UTC)
Source: CVE Database V5

Description

Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/05/2026, 21:28:51 UTC

Technical Analysis

CVE-2025-56400 is a CSRF vulnerability in the OAuth flow of the Tuya SDK 6.5.0 used in Tuya Smart, Smartlife, and other third-party apps. The OAuth implementation fails to validate the state parameter during the account linking process, enabling attackers to perform a CSRF-like attack. By convincing a victim to click a malicious authorization link, an attacker can complete the OAuth linking flow on behalf of the victim, associating the attacker’s Amazon Alexa account with the victim’s Tuya account. This grants unauthorized Alexa access to the victim’s smart devices controlled via Tuya, potentially allowing remote control of sensitive devices such as cameras, doorbells, door locks, and alarms. The vulnerability is exploitable without the Tuya app running and regardless of whether the victim previously linked Alexa to their Tuya account. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability.

Potential Impact

Successful exploitation allows an attacker to link their own Amazon Alexa account to a victim’s Tuya account without the victim’s consent. This unauthorized linkage can lead to remote control of smart home devices connected through Tuya, including cameras, doorbells, door locks, and alarms. The compromise affects user confidentiality, integrity, and availability of their smart home environment. The attack requires user interaction (clicking a crafted link) but no prior Alexa linkage or active Tuya app is needed.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users and administrators should be cautious about clicking unsolicited authorization links related to Tuya or Alexa integrations. Developers integrating the Tuya SDK should verify OAuth state parameter validation is correctly implemented to prevent CSRF attacks. Monitor vendor communications for updates and apply official patches once released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
mitre
Date Reserved
2025-08-16T00:00:00.000Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6924bdd9228e5e38741e15f1

Added to database: 11/24/2025, 20:19:37 UTC

Last enriched: 07/05/2026, 21:28:51 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 259

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses