Belkin fixes WEMO security vulnerabilities

Earlier today security services company IOActive released a statement detailing potential vulnerabilities it had discovered in the popular Belkin Wemo range of remote or smart home switches.  Belkin has this evening responded to the reports with news of updates and patches that fix what it describes as potential vulnerabilities.

Belkin WEMO Switch

iOActive’s claims are complex and rather technical, however any potential unauthorised control of the Wemo switches or more worrying the sensors or cameras should be of concern to owners and users.

The IOActive release said “Mike Davis, IOActive’s principal research scientist, uncovered multiple vulnerabilities in the WeMo product set that gives attackers the ability to:

  • Remotely control WeMo Home Automation attached devices over the Internet
  • Perform malicious firmware updates
  • Remotely monitor the devices (in some cases)
  • Access an internal home network

Now personally, the worst thing that could happen to me is that some geek turns on my bedroom light while I’m sleeping, however with many people using the Belkin Wemo cameras and other sensors there is a justified concern for these remote systems.

Belkin today responded to several twitter conversations I was having with concerned users with a link to a statement outlining how the vulnerabilities had been fixed.  That statement is here and I’ve reproduced it below.  Belkin Wemo users should check this and ensure their app and device firmware is up to date.

Security vulnerabilities published in CERT advisory fixed

Belkin has corrected the list of five potential vulnerabilities affecting the WeMo line of home automation solutions that was published in a CERT advisory on February 18. Belkin was in contact with the security researchers prior to the publication of the advisory, and, as of February 18, had already issued fixes for each of the noted potential vulnerabilities via in-app notifications and updates. Users with the most recent firmware release (version 3949) are not at risk from these malicious firmware attacks or remote control or monitoring of WeMo devices from unauthorized devices. Belkin urges such users to download the latest app from the App Store (version 1.4.1) or Google Play Store (version 1.2.1) and then upgrade the firmware version through the app. Specific fixes Belkin has issued include:

1) An update to the WeMo API server on November 5, 2013 that prevents an XML injection attack from gaining access to other WeMo devices. 

2) An update to the WeMo firmware, published on January 24, 2014, that adds SSL encryption and validation to the WeMo firmware distribution feed, eliminates storage of the signing key on the device, and password protects the serial port interface to prevent a malicious firmware attack 

3) An update to the WeMo app for both iOS (published on January 24, 2014) and Android (published on February 10, 2014) that enables the most recent firmware update

Trevor Long

Trev is a Technology Commentator, Dad, Speaker and Rev Head. He produces and hosts two popular podcasts, EFTM and Two Blokes Talking Tech. He also appears on over 50 radio stations across Australia weekly, and is the resident Tech Expert on Channel 9’s Today Show each day and appears regularly on A Current Affair. Father of three, he is often found down in his Man Cave. Like this post? Buy Trev a drink!

Recent Posts

  • News

AirBNB announce fun new Icon experiences letting you rub shoulders with the stars and more

Finding a fun experience while on a holiday is even easier, with AirBNB announcing Icons,…

12 hours ago
  • News

NSW Police arrest Sydney man over alleged data breach of Club sign-in data

After 24 hours of news and speculation around a potential privacy breach of up to…

12 hours ago
  • Tech

Ring introduces their first indoor camera that you can pan and tilt remotely

Ring has expanded their indoor security camera lineup once again, this time with a camera…

13 hours ago
  • Tech

Nab yourself a discount on LG’s top of the range UltraGear and UHD 4K gaming monitors

It’s a good time to look at updating your gaming monitor, with LG slashing prices…

19 hours ago
  • Tech

Review: Sennheiser MOMENTUM Sport — quality sound while recording your heart rate and body temperature

It was just a few weeks ago that I reviewed the Sennheiser Momentum True Wireless…

20 hours ago
  • Motoring

Nissan Z NISMO now part of the line-up after first 100 cars sold out in 53 minutes

The flagship NISMO edition is now a permanent part of the Nissan Z sports-car range…

23 hours ago