Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug

Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.



Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.

Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums


You may also be interested in this

Today in Apple history: i…

On December 18, 2006, the iPhone was announced -- but it wasn't made by Apple. Instead, it was a new product from Cisco. (via Cult of Mac - Tech and

Apple to Release watchOS …

Apple revealed during Tuesday's "Wonderlust" event that watchOS 10 will be released for Apple Watch Series 4 and later models on Monday, September 18. When the update rolls out, users

Twitter emergency alerts …

Twitter emergency alerts were one of the casualties of the company starting to charge for the API access that allows automatic tweeting. Many public services and transport companies were facing

USB-C AirPods Pro 2 may t…

Apple's next version of the AirPods Pro equipped with USB-C will ship this fall, a report claims, and it may even help users discover hearing problems too.An AirPods Pro caseApple

Apple releases fifth Deve…

Apple has started rolling out the fifth developer beta of watchOS 10 with essential bug fixes, according to… The post Apple releases fifth Developer Beta of watchOS 10 appeared first

Apple Stock Falls as Trum…

Apple's efforts to diversify its supply chain may have been for naught with the Trump administration's new tariffs that target multiple countries where Apple sources components for its iPhones, iPads,

Best MagSafe portable bat…

Macworld Portable power banks that charge your phone are popular, but wireless battery packs using Apple’s MagSafe technology offer a simpler and smarter cable-free solution for iPhone 12, 13 and

How to use the new passwo…

With the forthcoming macOS Sonoma, you'll be able to share usernames and passwords with family and friends from within Safari.Ever since Safari has been able to store and create passwords,
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.