logo

Wemo won’t fix Smart Plug vulnerability allowing remote operation

ID: bb7a45af-607b-5d0f-9931-9725be5029a3

STIX ID: report--bb7a45af-607b-5d0f-9931-9725be5029a3

Feed Name: Ars Technica Security

Threat Score
45/100

Date Published: 2023-05-16

Date Updated: 2026-04-19

Author: Kevin Purdy

...
...

The report discusses insecure Belkin Wemo smart plugs and the pyWeMo community library that allow unauthenticated network commands and may be exploitable via the cloud interface; it recounts past firmware password leaks and a lingering CVE reported around 2018–2019, recommends isolating devices from the Internet and segmenting them on a subnet, and notes Belkin's reluctance to adopt local-only Matter support as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.