CVE-2025-56400: n/a
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
AI Analysis
Technical Summary
CVE-2025-56400 is a CSRF vulnerability in the OAuth flow of the Tuya SDK 6.5.0 used in Tuya Smart, Smartlife, and other third-party apps. The OAuth implementation fails to validate the state parameter during the account linking process, enabling attackers to perform a CSRF-like attack. By convincing a victim to click a malicious authorization link, an attacker can complete the OAuth linking flow on behalf of the victim, associating the attacker’s Amazon Alexa account with the victim’s Tuya account. This grants unauthorized Alexa access to the victim’s smart devices controlled via Tuya, potentially allowing remote control of sensitive devices such as cameras, doorbells, door locks, and alarms. The vulnerability is exploitable without the Tuya app running and regardless of whether the victim previously linked Alexa to their Tuya account. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to link their own Amazon Alexa account to a victim’s Tuya account without the victim’s consent. This unauthorized linkage can lead to remote control of smart home devices connected through Tuya, including cameras, doorbells, door locks, and alarms. The compromise affects user confidentiality, integrity, and availability of their smart home environment. The attack requires user interaction (clicking a crafted link) but no prior Alexa linkage or active Tuya app is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users and administrators should be cautious about clicking unsolicited authorization links related to Tuya or Alexa integrations. Developers integrating the Tuya SDK should verify OAuth state parameter validation is correctly implemented to prevent CSRF attacks. Monitor vendor communications for updates and apply official patches once released.
CVE-2025-56400: n/a
Description
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-56400 is a CSRF vulnerability in the OAuth flow of the Tuya SDK 6.5.0 used in Tuya Smart, Smartlife, and other third-party apps. The OAuth implementation fails to validate the state parameter during the account linking process, enabling attackers to perform a CSRF-like attack. By convincing a victim to click a malicious authorization link, an attacker can complete the OAuth linking flow on behalf of the victim, associating the attacker’s Amazon Alexa account with the victim’s Tuya account. This grants unauthorized Alexa access to the victim’s smart devices controlled via Tuya, potentially allowing remote control of sensitive devices such as cameras, doorbells, door locks, and alarms. The vulnerability is exploitable without the Tuya app running and regardless of whether the victim previously linked Alexa to their Tuya account. The CVSS 3.1 base score is 8.8, reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to link their own Amazon Alexa account to a victim’s Tuya account without the victim’s consent. This unauthorized linkage can lead to remote control of smart home devices connected through Tuya, including cameras, doorbells, door locks, and alarms. The compromise affects user confidentiality, integrity, and availability of their smart home environment. The attack requires user interaction (clicking a crafted link) but no prior Alexa linkage or active Tuya app is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users and administrators should be cautious about clicking unsolicited authorization links related to Tuya or Alexa integrations. Developers integrating the Tuya SDK should verify OAuth state parameter validation is correctly implemented to prevent CSRF attacks. Monitor vendor communications for updates and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-08-16T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6924bdd9228e5e38741e15f1
Added to database: 11/24/2025, 20:19:37 UTC
Last enriched: 07/05/2026, 21:28:51 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 259
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.