Jump to content

Wemo

From Consumer_Action_Taskforce
Revision as of 18:45, 24 February 2025 by Mr Pollo (talk | contribs) (wayback machine is giving me 503 errors right now.)

⚠️ Article status notice: This article has been marked as incomplete

This article needs additional work to meet the wiki's Content Guidelines and be in line with our Mission Statement for comprehensive coverage of consumer protection issues.

This notice will be removed once sufficient documentation has been added to establish the systemic nature of these issues. Once you believe the article is ready to have its notice removed, visit the discord and post to the #appeals channel.

Learn more ▼

Wemo
Basic information
Founded 2012
Type Subsidiary
Industry Smart home
Official website wemo.com (https://www.belkin.com/products/wemo-smart-home/)

Wemo is a subsidiary of Belkin founded in 2012. They are known for smart home devices such as plugs and light switches that use the HomeKit and Thread protocols.

Consumer impact summary

Screenshot of account closure screen.

Through the app, users can delete their account by pressing the "close account" button, which will warn that Wemos cannot be controlled through the app once account data is deleted. The devices can also work by only using the Apple Home app, which does not require a Wemo account to set up.

Since 2022, the privacy policy of Belkin and Wemo have merged, sharing the same terms with each other. The data collected on users includes __. Belkin shares this info with marketing partners unless the user opts-out.[1] Users are allowed to make requests to access, withdraw consent, object, and delete most of the information Belkin has collected on them.[2] Belkin states they may need to hold onto information to "Defending Belkin against legal claims" or "Needing to respond to customer complaints and queries".[3]

The business model of Wemo is to sell smart home devices without the user paying for a subscription service. Although this may seem like a pro-consumer move, the Wemo experience has been diminished due to the lack of income streams. According to the App Store, the app once had a 3-year window without updates, which lasted between February 23, 2021 and May 28, 2024 (the current version as of February 24, 2025).[4]

Market control of Wemo has been decreasing over the years, as Wemo is only selling three devices[5], down from nine the year prior.[6]

Incidents

Security vulnerabilites

On November 5, 2013, Wemo updated its API to prevent future XML injection attacks.[7]

On May 16, 2023, multiple websites reported a Sternum study regarding a buffer overflow vulnerability in the Wemo Mini Smart Plug V2.[8] The study mentions the device could be exploited through a program called pyWemo[9] and potentially through cloud controls.[10] In their official response, Wemo stated "we believe that bad actors cannot exploit this vulnerability unless they have access to the user’s local network"[11] and "We discontinued the Wemo Mini Smart Plug v2 (F7C063) in 2020"[12], despite not making this information publicly available prior. During this report, the Wemo app hadn't been updated in 2 years, with the most recent update being on February 23, 2021, as previously mentioned.[4]

Products

  • Dimmers
    • Wemo Smart Dimmer[13]
    • Wemo WiFi Smart Dimmer[14]
  • Doorbells
    • Wemo Smart Video Doorbell[15]
  • Light switches
    • Wemo Smart Light Switch with Thread[16]
    • Wemo WiFi Smart Light Switch[17]
    • Wemo Smart Light Switch 3-Way[18]
  • Plugs
    • Wemo Smart Plug with Thread[19] (release date): Short summary of the product's incidents.
    • Wemo WiFi Smart Outdoor Plug[20]
  • Scene controller
    • Wemo Scene Controller with Thread[21]


References

  1. https://www.belkin.com/legal/privacy-policy/#marketing-anchor
  2. https://www.belkin.com/legal/privacy-policy/#your-rights-in-relation
  3. https://www.belkin.com/legal/privacy-policy/#retention-of
  4. 4.0 4.1 https://apps.apple.com/us/app/wemo/id511376996
  5. https://web.archive.org/web/20240225173134/https://www.belkin.com/products/wemo-smart-home/
  6. https://web.archive.org/web/20230201232551/https://www.belkin.com/products/wemo-smart-home/
  7. https://www.belkin.com/support-article/?articleNum=80322
  8. https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
  9. https://thehackernews.com/2023/05/serious-unpatched-vulnerability.html
  10. https://www.theverge.com/2023/5/16/23725290/wemo-smart-plug-v2-smart-home-security-vulnerability
  11. https://x.com/WEMOcares/status/1658963426230562819
  12. https://x.com/WEMOcares/status/1658963635882938374
  13. https://web.archive.org/web/20221130043724/https://www.belkin.com/smart-dimmer/P-WDS070.html
  14. https://web.archive.org/web/20221129001529/https://www.belkin.com/wifi-smart-dimmer/P-WDS060.html
  15. https://www.belkin.com/p/smart-video-doorbell/WDC010.html
  16. https://www.belkin.com/p/smart-light-switch-with-thread/WLS0503.html
  17. https://web.archive.org/web/20221130045654/https://www.belkin.com/wifi-smart-light-switch/WLS040-CA.html
  18. https://web.archive.org/web/20221129145512/https://www.belkin.com/smart-light-switch-3-way/P-WLS0403.html
  19. https://web.archive.org/web/20230910113415/https://www.belkin.com/smart-plug-with-thread/WSP100.html
  20. https://web.archive.org/web/20221201141200/https://www.belkin.com/wifi-smart-outdoor-plug/WSP090.html
  21. https://www.belkin.com/p/scene-controller-with-thread/WSC010.html