Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wvu

#34633of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2019-12940
7.5
2019-06-10
Belkin · Wemo · CVE-2019-12780
**Name of the Vulnerable Software and Affected Versions** Belkin Wemo Enabled Crock-Pot (affected versions not specified) **Description** The issue concerns command injection in the Wemo UPnP API. Specifically, it affects the `SmartDevURL` argument to the `SetSmartDevInfo` action. An attacker can exploit this by sending a simple POST request to the "/upnp/control/basicevent1" API endpoint, allowing the execution of commands without requiring authentication. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.