logo elektroda
logo elektroda
X
logo elektroda

Tuya W509Z1 RGBCT Bulb Compatibility with Cloudcutter Exploit on Firmware 1.0.0

tadeu1 312 2
ADVERTISEMENT
  • #1 21835151
    tadeu1
    Level 5  
    I have this bulb W509Z1

    I buy here
    https://pt.aliexpress.com/item/10050072549962...in.77.20f9caa4zlyBHD&gatewayAdapt=glo2bra

    and it have 1.0.0 and mcu 1.0.0
    But I think this exploit its not for my version, is it possible to add the version 1.0.0, its hard to take out the pcb from light because the wire in the bottom

    https://github.com/tuya-cloudcutter/tuya-clou...s/tuya-generic-1947z5r-w509z1-rgbct-bulb.json

    Added after 1 [minutes]:


    Ubuntu screen with terminal logs for scanning Tuya SmartLife AP and running tuya-cloudcutter
  • ADVERTISEMENT
  • #2 21835392
    k45i89o98j66
    Level 39  
    CloudCutter exploits a 'vulnerability' in the Tuya software of older devices that:

    accept unauthorised OTAs,

    do not have the newer Tuya SDK security features,

    allow device profile and firmware to be uploaded without a signature.


    Vulnerability does not depend on version "1.0.0" in general - only on:

    🔹 the version of the Tuya SDK used in the compilation,
    🔹 the specific chipset (BK7231T/BK7231N/RTL8720CF),
    🔹 the list of available profiles for the device in question.

    Added after 1 [minute]:

    CloudCutter is more of a technical exploit / firmware hack

    Added after 47 [seconds]:

    Tuya W509Z1 RGBCT bulb with Cloudcutter exploit on firmware 1.0.0 Yes is not compatible.
  • #3 21836109
    tadeu1
    Level 5  
    thanks
    there's Bulb with a easy way to access the point to solder? I have 4, and they are impossible to access without broken the connector wires.
ADVERTISEMENT