๐Ÿ” CVE Alert

CVE-2026-3465

LOW 3.1

Tuya App/SDK JSON Data Point denial of service

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. There is ongoing doubt regarding the real existence of this vulnerability. The vendor disagrees with the conclusion of the finding: "The described vulnerability fails to prove its feasibility or exploitability by attackers. The issue essentially does not constitute a security vulnerability, aligning more closely with abnormal product functionality." These considerations are properly reflected within the CVSS vector.

CWE CWE-404
Vendor tuya
Product app
Published Mar 3, 2026
Last Updated Mar 3, 2026
Stay Ahead of the Next One

Get instant alerts for tuya app

Be the first to know when new low vulnerabilities affecting tuya app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tuya / App
24.07.11
Tuya / SDK
24.07.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.348536 vuldb.com: https://vuldb.com/?ctiid.348536 vuldb.com: https://vuldb.com/?submit.744108 github.com: https://github.com/deopllj/Device_CVE_Archive/blob/main/Yonganda%20YAD-LOJ%20CVE%20Doc.pdf

Credits

๐Ÿ” deoplljj (VulDB User)