Update – Virtual Vandalism: Firm Warns Of Connected Home Security Holes
ID: fddeb876-9522-546e-b846-789866390e2a
STIX ID: report--fddeb876-9522-546e-b846-789866390e2a
Feed Name: Security Ledger
Threat Score
IOActive disclosed several serious vulnerabilities in Belkin WeMo home automation devices — leaked firmware signing keys enabling malicious firmware updates, absence of SSL certificate validation, a proprietary protocol allowing direct device access, and an XML inclusion flaw — which could permit remote takeover, privacy invasion, and even physical harm; Belkin subsequently released firmware (v3949) and API/app updates to address the reported issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
