Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

New iPad Pro, MacBook Pro…

Apple is preparing day-one software updates for its new iPad Pro, MacBook Pro, and Vision Pro models. iPadOS 26.0.1 (23A8464), macOS 26.0.1 (25A8364), and visionOS 26.0.1 (23M8340) should be available

Create pro-quality videos…

Macworld Looking for an easy way to improve your webcam output without having to invest a lot of money on software and equipment? Then FineCam Pro is exactly what the

CarPlay & Android Aut…

Recent data indicates that nearly every newly manufactured car now comes equipped with either Apple CarPlay or Android Auto, responding to the growing consumer preference for these connectivity features.Tesla had

How to use SFTP and rsync…

SFTP and rsync are two tools that can help you transfer files across networks and the web. Here's how to use them within macOS.You can use SFTP and rsync on

Final Cut Pro said to be …

According to YouTuber and filmmaker Matti Haapoja, Final Cut Pro will be available for the Apple Vision Pro at launch — but it's not clear exactly how.Final Cut Pro running

iOS 17 Compatible With iP…

Apple today announced that iOS 17 is compatible with the iPhone XS and newer, meaning that support has been dropped for the iPhone 8, iPhone 8 Plus, and iPhone X.

How to use Safari Profile…

Apple has added a new Profiles feature to Safari in macOS Sonoma, which is meant to be a quick way to separate work and home browsing, and to help with

Apple’s Tap to Pay now av…

Apple has announced today that it has launched Tap to Pay on the iPhone in the United Kingdon… The post Apple’s Tap to Pay now available in the United Kingdom
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.