Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug

Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.



Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.

Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums


You may also be interested in this

iPhone beats Android flag…

While no smartphone repair is so simple a child could do it, the iPhone 13 is among the most straightforward models to repair at home, a report claims, handily beating

‘Weather Up’ …

Weather Up today was updated with a few new features, including an interactive Home Screen widget and an Apple Watch app. The interactive widget allows you to view your local

iOS 17 continues personal…

Following months of rumors and speculation, Apple has used WWDC 2023 to reveal iOS 17, its next milestone operating system release for the iPhone.Shown off during the annual Worldwide Developer

17 noteworthy iOS 17 feat…

Macworld Apple had plenty of great things to show off when it unveiled iOS 17 at WWDC. We’re psyched about vastly improved autocorrect, StandBy, Live Voicemail transcriptions, custom contact posters,

Apple releases first iOS …

Apple on Friday released the first iOS 16.6 beta for developers just one day after the public release of iOS 16.5. The update comes on the same day that the

iPhone 17 Drops Select 5G…

Apple’s iPhone 17 lineup, including the premium Pro models and the sleek new iPhone Air, brings exciting hardware… The post iPhone 17 Drops Select 5G Bands: A Closer Look at

Many of Apple’s products …

Apple’s next-gen iPhone operating system, iOS 17, due this fall, will feature an update to autocorrect, powered by AI, that will no longer change the F-word to “duck.” Caroline Mimbs

Samsung’s summer sa…

Now through May 22nd, shoppers can save big on a wide range of popular Samsung products. The Discover Samsung Summer event delivers deals across multiple categories, including mobile phones, computer
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.