TIANJIN XINHENG INDUSTRY TRADING CO.,LTD
Home Home
About US
Products
Exhibition
Glories
Projects
Security Bulletins
Security Updates
Contact Us

Security Bulletins

Security Announcement - Tuya APP CSRF Vulnerability 

Addtime:2025-09-09 10:42:05

Summary:

There is a CSRF vulnerability in the Tuya APP under specific circumstances.

Risk Level:

High

CVSS (Base Score):

8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Conditions:

Attackers can use carefully crafted malicious links and Proof of Concept (PoC) code, combined with social engineering techniques, to induce users to trust and click on malicious links. This may involve disguising as trustworthy content or sources to increase the probability of success.

Risk:

This vulnerability could be exploited by malicious actors to launch CSRF attacks. Under certain conditions, this may allow attackers to bypass user permission restrictions and perform unauthorized actions on affected devices. Users should remain vigilant and avoid clicking on suspicious links.

Scope of Impact:

Affected versions of Tuya SDK: < 6.5.0; Affected version of Tuya Smart (iOS): 6.3.1; Affected version of Tuya Smart (Android): 6.3.1; Affected version of Smart Life (iOS): 6.3.4; Affected version of Smart Life (Android): 6.3.1;

Remediation Plan:

It is recommended that developers update the Tuya APP to version 6.5.0 or above to eliminate the impact of this vulnerability. Users should also regularly check for application version updates to ensure they use the latest and most secure version.


{aspcms:foot}