Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

AI-Powered text-based vid…

Adobe has officially updated Premiere Pro with text-based video editing. After a period of time in the beta version throughout this year, Adobe announced last month that the feature would

Play Bluetooth devices an…

The new R-40PM and R-50PM models upgrade design, pump up bass response and broaden connectivity with a phono preamp for turntables. (via Cult of Mac - Tech and culture through

iOS 17 accessibility feat…

Hear about iOS 17's new accessibility features, the WWDC "special activity," and the iCloud Drive woes that led your host to wipe his MacBook Pro on the AppleInsider Podcast.iOS 17

The new Apple Silicon Mac…

The Apple Silicon Mac Pro is here two and a half years after the shift from Intel began, but it looks like the company only did it to say that

Apple’s live events…

This year's WWDC keynote was another shiny, practiced, and well-oiled presentation for a bunch of new things coming down the pipe. It's a clear sign that Apple's is probably done

Apple’s ‘XR&#…

A leak claims Apple's name for its mixed-reality headset will be "XR," but the same rumor claims a questionable starting price of $1,999, not the previously-rumored $3,000.[Yeux1122/Naver]Apple is mere hours

How to get Apple TV &…

You should bring creature comforts if you're stuck in a hotel for a long period of time. Here's how to get going with an Apple TV, HomePod, or both while

iPhone 16 Pro and Pro Max…

Macworld At a glanceExpert's Rating Pros Camera Control can be very useful Fantastic battery life Outrageous performance Cons Camera Control can also be finicky Apple Intelligence is not yet available
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.