Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

APPL $3T valuation isn’t …

We’ve been keeping a close eye on the ticker tape (ok, the Stocks app) as it seems that any day now could see a milestone APPL $3T valuation. But as

Report: Apple’s new C1 mo…

Macworld In the technical data of the Apple iPhone 16e, the parameters for fast charging—50 percent in 30 minutes with compatible hardware—and for wireless charging with Qi devices can be

Apple developer betas are…

Apple has quietly updated its developer program with a free tier that includes access to developer betas, so any user who’d like to try them on non mission-critical hardware no

Best Apple Deals of the W…

This week we began tracking a series of discounts on Apple's just-released 15-inch MacBook Air, and it's now sitting at a $100 discount on Amazon. Besides this great deal, we're

Review: Sony’s new XB100 …

Earlier this spring, Sony announced the latest addition to its family of portable Bluetooth speakers. Now with summer just starting to get cozy, we’re taking a look at just how

Apple Watch calls 911 for…

The Apple Watch Fall Detection feature helped a woman get medical attention after collapsing, caused by suffering from a major and potentially fatal heart issue.Fall Detection in the Apple Watch

Get 20% off OWC Atlas mem…

Expand your storage capacity and speed up file transfers. OWC Atlas memory cards and select card readers are 20% off for AppleInsider readers now through May 31.Save 20% on OWC

AirTags are a must-have f…

Apple’s AirTag item tracker has become a fan-favorite accessory for a number of reasons. Whether you’re trying to find your keys that you’re ‌positive are somewhere in the house, or
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.