Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug
Older Wemo smart plugs from Belkin have a vulnerability that allows them to be hacked, according to a blog post from security researchers at Sternum. The Wemo Mini Smart Plug V2 (model F7C063) from 2019 is vulnerable to a buffer overflow attack that can be used execute commands remotely.


Basically, the Wemo Mini Smart Plug V2 has a 30 character name limit that can be overwritten, leading to an exploitable memory buffer error. Full details on how the exploit works are available from Sternum.

Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years and has been replaced with newer models. That leaves many potential Belkin customers vulnerable, as there are likely many of these smart plugs being used in the wild.

Sternum recommends that people prevent the Wemo Mini Smart Plug V2 from accessing the internet and communicating with other devices like the iPhone because of the vulnerability, but the safest bet would be to remove the plugs and replace them with something more secure.
Tags: Belkin, Wemo

This article, "PSA: Older Wemo Smart Plugs Have Vulnerability That Leaves Them Open to Attack" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

Get this luxurious Twelve…

Macworld We know the feeling—your desk always becomes a complete mess when you start spreading cables and charging your devices, especially since both your iPhone and your Apple Watch need

Apple appears to have dis…

It looks like Apple has stopped selling the iPhone 14. The device, first released in 2022, seems to have vanished from Apple’s website following the launch of the iPhone 16E.

With iOS 17, Apple lets y…

Image: Vjeran Pavic / The Verge Apple’s AirTag item trackers are about to get more useful — with iOS 17, you’ll be able to share them and other Find My

Don’t judge Apple’s VR he…

Illustration: The Verge Just when the metaverse had mostly faded from the headlines, a heavily rumored new product launch appears poised to bring it roaring back. Today let’s talk about

Apple Card Monthly Instal…

Apple is changing Apple Card financing terms for iPhone and Apple Watch in time for the new device season.How an iPhone is financed with Apple Card is changingApple Card Monthly

Apple Explains How to Fix…

Apple today updated its iMessage troubleshooting support document to add a scenario that can occur in iOS 26. If you don't activate iMessage or an eSIM when setting up a

Apple’s unique head…

Despite suppliers hitting significant production roadblocks with curved components, Apple's headset is still rumored for a WWDC reveal with mass production later in 2023.Apple's headset is a challenge for manufacturersApple's

Small developers saw a 71…

Analysts have found that small developers on the App Store have outpaced large developers, growing their revenue by more than 70% between 2020 and 2022.Image Credit: AppleThe study, dubbed "Small
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.