
CVE-2026-28522 arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send … https://www.cve.org/CVERecord?id=CVE-2026-28522
Post summary
The post announces a null pointer dereference vulnerability in Arduino‑TuyaOpen prior to version 1.2.1 that can be triggered by a local attacker; no PoC, exploit code, or patch information is provided.
