Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Apple Stops Signing iOS 1…

Apple today stopped signing iOS 17.6, preventing iPhone users from downgrading to that version of iOS. The update is no longer being signed after Apple released iOS 17.6.1 on August

Apple TV+ renews ‘The Mor…

“The Morning Show” drama series on Apple TV+, starring Jennifer Aniston and Reese Witherspoon, will return for a fourth season on Apple TV+. The early renewal comes ahead of the

Sonnet updates Echo 11 Th…

Sonnet's Echo 11 Thunderbolt 4 HDMI Dock updates its predecessor with a new video option, more power delivery, and even faster network connectivity.Sonnet Echo 11 Thunderbolt 4 HDMI DockSonnet launched

Apple Music down for some…

Apple Music is not working for some users this morning. While many are complaining about the trouble on Twitter and elsewhere, Apple hasn’t officially acknowledged the downtime yet. In the

Apple and global supplier…

Apple today announced its manufacturing partners now support over 13 gigawatts of renewable electricity around the world.

Daily deals June 16: Appl…

Today's hottest deals include 30% off a 2020 27" iMac, 36% off an Anker foldable 3-in-1 wireless charging station, 20% off Tile item finders, 22% off a Google Nest cam,

Apple has finally removed…

Update four months later: A fake Microsoft Authenticator app somehow survived the cull, but was finally removed in June … more… The post Apple has finally removed fake Microsoft Authenticator

Apple will not buy Disney…

The rumor that Apple will buy Disney is old enough to buy an overpriced beer at EPCOT. And, after Disney's Bob Iger appeared at WWDC, it's back yet again, this
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.