Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Clckr’s Stand &…

Clckr's Stand & Grip for iPhone is a MagSafe-compatible accessory that's good for the office but isn't one we'd trust to hold our phone for our next vacation sunset and

Online Apple Store opens …

Customers in Vietnam can now shop for Apple products via Apple's online store.Hello VietnamApple's online store has been a staple of the company since Steve Jobs' return in 1997. However,

It wasn’t a mistake…

Apple has quietly updated its developer program with a free tier that includes access to developer betas, but we still can't recommend installing beta software.Developers only need a free Apple

tvOS 16: Immersive Entert…

In the ever-evolving landscape of digital entertainment, Apple continues to push boundaries with each iteration of its tvOS. With the release of tvOS 16, Apple introduces a myriad of features

Wedbush raises Apple stoc…

Analysts at investment firm Wedbush have raised their Apple target price by $15, based on predictions of success for the Vision Pro headset, iPhone 15 range, and Apple services.In April

Apple’s latest ‘The Under…

Still from Apple’s latest ‘The Underdogs’ video Apple’s official YouTube channel just got a new addition: a humorous video titled “The Underdogs: OOO (Out of Office)”. This 10-minute short follows

Apple’s WWDC 2023 A…

Ahead of Apple's keynote event at WWDC on Monday, June 5, the company's annual "AR experience" easter egg is now available. Apple's imagery for WWDC 2023 has a bubble-like theme

Threads hasn’t been…

Twitter's attorneys are already threatening the nascent Threads with a lawsuit for stealing trade secrets and misuse of intellectual property.The letter, sent by the Quinn Emanuel law firm, claims that
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.