logo

Update – Virtual Vandalism: Firm Warns Of Connected Home Security Holes

ID: fddeb876-9522-546e-b846-789866390e2a

STIX ID: report--fddeb876-9522-546e-b846-789866390e2a

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2014-02-18

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

IOActive disclosed several serious vulnerabilities in Belkin WeMo home automation devices — leaked firmware signing keys enabling malicious firmware updates, absence of SSL certificate validation, a proprietary protocol allowing direct device access, and an XML inclusion flaw — which could permit remote takeover, privacy invasion, and even physical harm; Belkin subsequently released firmware (v3949) and API/app updates to address the reported issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.