Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Halide Camera Team Launch…

The developers behind popular photography app Halide today announced the launch of Kino, an app designed for capturing cinematic video. Kino has the tools that professionals need while also providing

Apple and Disney partner …

Disney CEO Bob Iger made a surprise appearance during the WWDC keynote to announce that the Disney+ app will launch on Apple Vision Pro with 3D interactive experiences from "Star

Apple releases sixth Deve…

Apple has started rolling out the sixth developer beta of watchOS 10 with essential bug fixes, according to… The post Apple releases sixth Developer Beta of watchOS 10 appeared first

Here’s why Apple’s latest…

Although Apple has always tried to sell the idea that its devices are great for gaming, the company’s platforms lack many popular console-level titles – partly because Apple has super-restrictive

Apple Card Savings custom…

The accounts launched to great acclaim with their high yield, but some customers complained getting their money takes too long. (via Cult of Mac - Tech and culture through an

After years of silence, t…

Apple has at long last released a trailer for "Killers of the Flower Moon," an upcoming Western drama from Martin Scorsese that stars Leonardo DiCaprio and Mollie Kyle."Killers of the

Apple Silicon Mac Pro doe…

Apple announced the Apple Silicon Mac Pro, and while it packs a punch with M2 Ultra, pro users won't be happy with a lack of Radeon PCI-E video card support.Apple

How to make the new iPhon…

I stumbled across an alternative way to use the iPhone Camera Control that makes the new feature less irritating. (via Cult of Mac - Apple news, rumors, reviews and how-tos)
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.