Wemo: Difference between revisions
mNo edit summary |
Added info to the vulnerabilities section |
||
| Line 27: | Line 27: | ||
==Incidents== | ==Incidents== | ||
===Security vulnerabilites=== | ===Security vulnerabilites=== | ||
On November 5, 2013, Wemo updated its API to prevent future XML injection attacks.<ref>https://www.belkin.com/support-article/?articleNum=80322</ref> | |||
On May 16, 2023, multiple websites reported a Sternum study regarding a buffer overflow vulnerability in the Wemo Mini Smart Plug V2.<ref>https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/</ref> The study mentions the devices could be exploited through cloud controls.<ref>https://www.theverge.com/2023/5/16/23725290/wemo-smart-plug-v2-smart-home-security-vulnerability</ref> In their official response, Wemo stated "we believe that bad actors cannot exploit this vulnerability unless they have access to the user’s local network."<ref>https://x.com/WEMOcares/status/1658963426230562819</ref> During this report, the Wemo app hadn't been updated in 2 years, with the most recent update being on February 23, 2021.<ref>https://apps.apple.com/us/app/wemo/id511376996</ref> | |||
==Products== | ==Products== | ||
Revision as of 20:30, 20 February 2025
⚠️This article has been marked as incomplete. Sourcing or verifiability needs additional work.
#appeals channel in either Zulip or Discord to request removal.Articles must provide verifiable, credible evidence for their claims and avoid relying on forum posts, personal blogs, or other unverifiable sources. You can help by replacing weak citations with reputable reporting, corporate communications, receipts, repair logs, or independent investigative coverage that demonstrates the systemic relevance required by the Mission statement and Moderator Guidelines.
| Basic information | |
|---|---|
| Founded | 2012 |
| Legal structure | Subsidiary |
| Industry | Smart home |
| Official website | wemo.com (https://www.belkin.com/products/wemo-smart-home/) |
Wemo is a subsidiary of Belkin founded in 2012. They are known for smart home devices such as plugs and light switches that use the HomeKit and Thread protocols.
Consumer impact summary
Through the app, users can delete their account by pressing the "close account" button, which will warn that all account data will be deleted.
Incidents
Security vulnerabilites
On November 5, 2013, Wemo updated its API to prevent future XML injection attacks.[1]
On May 16, 2023, multiple websites reported a Sternum study regarding a buffer overflow vulnerability in the Wemo Mini Smart Plug V2.[2] The study mentions the devices could be exploited through cloud controls.[3] In their official response, Wemo stated "we believe that bad actors cannot exploit this vulnerability unless they have access to the user’s local network."[4] During this report, the Wemo app hadn't been updated in 2 years, with the most recent update being on February 23, 2021.[5]
Products
- Doorbells
- Wemo Smart Video Doorbell[8]
- Light switches
- Plugs
- Scene controller
- Wemo Scene Controller with Thread[14]
References
- ↑ https://www.belkin.com/support-article/?articleNum=80322
- ↑ https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
- ↑ https://www.theverge.com/2023/5/16/23725290/wemo-smart-plug-v2-smart-home-security-vulnerability
- ↑ https://x.com/WEMOcares/status/1658963426230562819
- ↑ https://apps.apple.com/us/app/wemo/id511376996
- ↑ https://web.archive.org/web/20221130043724/https://www.belkin.com/smart-dimmer/P-WDS070.html
- ↑ https://web.archive.org/web/20221129001529/https://www.belkin.com/wifi-smart-dimmer/P-WDS060.html
- ↑ https://www.belkin.com/p/smart-video-doorbell/WDC010.html
- ↑ https://www.belkin.com/p/smart-light-switch-with-thread/WLS0503.html
- ↑ https://web.archive.org/web/20221130045654/https://www.belkin.com/wifi-smart-light-switch/WLS040-CA.html
- ↑ https://web.archive.org/web/20221129145512/https://www.belkin.com/smart-light-switch-3-way/P-WLS0403.html
- ↑ https://web.archive.org/web/20230910113415/https://www.belkin.com/smart-plug-with-thread/WSP100.html
- ↑ https://web.archive.org/web/20221201141200/https://www.belkin.com/wifi-smart-outdoor-plug/WSP090.html
- ↑ https://www.belkin.com/p/scene-controller-with-thread/WSC010.html