Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Apple Fitness+ celebrates…

In celebration of Pride, Fitness+ is introducing new workouts and meditations, as well as a new Artist Spotlight featuring music by Madonna.

Deals: 11-inch M2 iPad Pr…

All of today’s best deals are now up for grabs and headlined by a notable discount on Apple’s Magic Keyboard for 11-inch iPad Pro. Now landing at the second-best price

Darkboard Drawing Accesso…

Astropad, known for its Astropad Studio software and Luna Display dongle for connecting an iPad to a Mac, today announced the general availability of its new Darkboard drawing surface designed

5 things Apple killed to …

Macworld After five years with the iPhone SE, there’s a new “budget” iPhone at the Apple Store today, the iPhone 16e. Not only did Apple completely shake up the low

AppleDB Offers Useful Dat…

Launched in 2022, AppleDB is a helpful resource that provides a database of Apple devices, software updates, firmware releases, and more. The website was recently updated with all macOS releases

Apple pitches Vision Pro …

Vision Pro users will have more than 150 3D movies and "the future of entertainment" -- Apple Immersive Video. (via Cult of Mac - Apple news, reviews and how-tos)

Apple Arcade FAQ: ‘Millio…

Macworld Gaming subscription services are all the rage now, but Apple Arcade isn’t quite like Google Stadia or Xbox Game Pass. So if you’ve got questions about it, we’ve got

Leaker shows off the four…

Macworld The iPhone’s Pro-model colors are rarely exciting. Leaker Sonny Dickson has revealed a new image of dummy units that purportedly show off the new colors for the upcoming iPhone
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.