PT-2023-2988 · Belkin · Wemo Mini Smart Plug V2+1
Amit Serper
+1
·
Publicado
2023-02-27
·
Atualizado
2025-01-22
·
CVE-2023-27217
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Belkin Smart Outlet V2 F7c063 firmware 2.00.11420.OWRT.PVT SNSV2
Wemo Mini Smart Plug V2 (F7C063)
Description
A stack-based buffer overflow in the ChangeFriendlyName() function allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request. The issue is related to the function that permits changing the default assigned name, with a name length limited to 30 characters or less, but this rule is only applied by the application itself. Bypassing the character limit using a Python module named pyWeMo can lead to a buffer overflow state, which can then be used to crash the device or execute malicious commands.
Recommendations
For Belkin Smart Outlet V2 F7c063 firmware 2.00.11420.OWRT.PVT SNSV2, consider disabling the ChangeFriendlyName() function until a patch is available.
For Wemo Mini Smart Plug V2 (F7C063), restrict access to the device from the internet and ensure network segmentation measures are in place to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Belkin Smart Outlet V2
Wemo Mini Smart Plug V2