Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

iPhone 15 Pro panel order…

Apple is currently in the process of readying the iPhone 15 lineup for launch this fall. Based on display supply chain analysis, Apple appears to be gearing up for especially

Apple’s online stor…

Backing up the expectation that new Macs will be announced at WWDC 2023, Apple has temporarily shut down its online store and posted a link to watch the keynote at

iMessage Contact Key Veri…

One of the first found feature changes in iOS 16.6 and iPadOS 16.6 may be an iMessage verification system that could help prevent government agencies from eavesdropping on the conversations

Grab a 4-pack of AirTags …

Macworld Apple’s AirTags are a great way to track anything that isn’t an Apple product—keys, wallets, luggage, etc. And today you can get four of them for just $20 each:

Apple’s Irish tax battle …

The outcome of the long-running Irish tax battle between Apple and the European Commission will be decided by Europe’s highest court, after the EC lodged a final appeal against the

Apple’s homegrown modem p…

Insanely great, Apple’s multi-year project to build its own modem is not; other than at incinerating untold billions of dollars, that is. Aaron Tilley and Yang Jie for The Wall

How Screen Time can keep …

Macworld It’s almost as if having your iPhone stolen is worse than having your house robbed. It’s not just losing an expensive device—your iPhone holds so much of your private

Apple Vision Pro $3,499 m…

Apple has unveiled its mixed-reality headset, the Vision Pro. Its ambitious launch of a new platform will make waves in the AR market, but it will ship in early 2024
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.