Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

The green bubble problem …

Image: Apple Apple has spent years slowly making green bubbles feel like a worse kind of message — no typing indicators, tiny photos, no end-to-end encryption — but those constraints

AirPods 4 with ANC crash …

Macworld Even at full price, we really like the AirPods 4 with ANC as an affordable alternative to AirPods Pro, but at this price, they’re impossible to pass up. Amazon

Daily deals: Apple Pencil…

Today's top deals include $250 off an Acer 27" gaming monitor, $100 off an M2 Mac mini & AppleCare kit, up to 86% off Kodak wireless Bluetooth speakers, 42% off

Why Apple Watch Ultra mig…

I used to write a lot about run tracking with the and how it performed during races. It’s been a while, though, because, well, I haven’t run much since the

Apple opposes UK bill tha…

Apple is the Online Safety Bill as it could be used to force encrypted messaging tools like iMessage, WhatsApp, Signal and other to scan messages for, ostensibly, child sexual abuse

A new iMessage bug is cau…

For some iPhone owners out there, a strange bug is potentially wreaking havoc on folks trying to text Android users.Messages iconThere are some iPhone users taking to social media to

All U.S. iPhones will com…

Macworld Until the company was granted an exemption a fortnight ago, President Trump’s ‘reciprocal’ tariffs threatened to be a major headache for Apple. A large proportion of its products are

Apple rolling out iOS 16.…

Apple last week introduced the first beta of iOS 16.6 to developers. Now the company is rolling out iOS 16.6 beta 2, along with updates to macOS 13.5 beta, watchOS
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.