Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

What keeps the Mac releva…

The Mac continues to enjoy strong consumer demand and serves a crucial purpose in supporting the functionality of the iPhone and the upcoming Vision Pro headset.Consumer demand for Mac remains

Google Announces End Date…

Google has announced that first- and second-generation Nest Learning Thermostats will lose support in October 2025, disabling their connected features (via ArsTechnica). After October 25, 2025, these devices will no

Apple’s AI future could b…

Macworld Everyone wants to talk about AI. Most of them don’t know what it is (artificial intelligence), but they still want to talk about it. Who’s got it and who

Citi initiates Apple cove…

Citi Research analyst Atif Malik late Thursday initiated coverage of Apple stock with a “Buy” rating and a $240 price target. Emily Bary for MarketWatch: “We believe the Street is

Learn how to play the pia…

Macworld Musicians often enjoy a good quality of life with less stress, added confidence, and more social opportunities. Want to take advantage of these benefits but don’t have time for

Daily Deals: 41% off Appl…

Today's hottest deals include 21% off a MagSafe charger, 53% off a 4-Pack of 160 feet outdoor LED solar string lights, 31% off a Pexxus 3-in-1 wireless charging station, and

Twitter Rolling Out Suppo…

Twitter appears to be adopting support for picture-in-picture mode on the iPhone and iPad, with some Twitter users reporting access to a feature that allows them to watch Twitter videos

Apple Shares 13-Minute &#…

Apple has shared a new action-packed film called "Huracán Ramírez vs. La Piñata Enchilada" on its YouTube channel as part of its Shot on iPhone series. The 13-minute video, filmed
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.