This repository will contain the write-up and toolchain of a wireless vulnerability that can jailbreak some of the latest smart devices built under various brand names by Tuya, after a disclosure period of 45 days since reporting it has passed or the vulnerability has been patched in Tuya's SDK.
Our tool disconnects Tuya devices from the cloud, allowing them to run completely locally. Additionally, it can be used to flash custom firmware to devices over-the-air.
Brand | Picture | Device description | Article number | Flash dump / firmware acquired? | Exploitable? |
---|---|---|---|---|---|
LSC | Smart Dimmer Switch | 3006033 970806 |
Yes | No | |
Smart Siren | 970772 v2.0 | No - not a BK7231 chip | No |