We select and review products independently. When you purchase through our links we may earn a commission. Learn more.

Belkin Refuses to Patch a Security Flaw In Wemo Smart Plug V2

A Wemo smart plug engulfed in flames.
Belkin (Modified)

Security experts at Sternum identified a critical vulnerability (CVE-2023-27217) in Belkin’s Wemo Smart Plug V2. When exploited, this vulnerability allows hackers to execute remote code—something that may compromise your entire network. But Belkin won’t fix it.

Before we get into the details, I should note that Sternum fulfilled this exploit through a direct connection with a Wemo Smart Plug V2. The security group believes that remote code execution could be enabled through the cloud (from outside of your home), but it has not confirmed this belief.

Anyway, Sternum alerted Belkin to this vulnerability. And it received a ridiculous response; in Belkin’s words, the Wemo Smart Plug V2 “is at the end of its life and will not be patched.”

It’s true that the Wemo Smart Plug V2 is a bit old. After all, Belkin is currently selling a fourth-gen model (which is not affected by this problem). But the product still works, it’s still in many homes, and if customers knew that their Wemo Smart Plug would become a security threat, they probably wouldn’t have bought it in the first place.

Even if you don’t own the second-gen Wemo Smart Plug, Belkin’s short-sighted response is alarming. How will this company deal with security vulnerabilities in its other products? (Unfortunately, this sort of response is growing increasingly common among smart home brands, who like to pretend that smart home devices should have a short shelf life.)

You can identify a Wemo Smart Plug by looking at the back of the device. Sternum suggests that businesses (or other sensitive networks) properly segment their Wemo Smart Plug V2 to keep it isolated from other devices. Home users should avoid exposing their smart plugs through port forwarding (which is good advice for any smart home device, frankly speaking).

The Best Smart Plugs of 2023

Kasa Smart Plug HS103P2, Smart Home Wi-Fi Outlet Works with Alexa, Echo, Google Home & IFTTT, No Hub Required, Remote Control,15 Amp,UL Certified, 2-Pack White
Best Smart Plug
Kasa Smart Plug HS103P2, Smart Home Wi-Fi Outlet Works with Alexa, Echo, Google Home & IFTTT, No Hub Required, Remote Control,15 Amp,UL Certified, 2-Pack White
Wyze Smart Plug
Best Budget Smart Plug
Wyze Smart Plug
Amazon Basics Outdoor Smart Plug
Best Outdoor Smart Plug
Amazon Basics Outdoor Smart Plug
Amazon Smart Plug, for home automation, Works with Alexa - A Certified for Humans Device
Best Amazon Alexa Smart Plug
Amazon Smart Plug, for home automation, Works with Alexa - A Certified for Humans Device
Vont Smart Plug
Best Smart Plug for Google Assistant
Vont Smart Plug
Eve Energy Smart Plug
Best Smart Plug for Apple HomeKit
Eve Energy Smart Plug

Source: Sternum via 9to5Mac

Andrew Heinzman Andrew Heinzman
Andrew is the News Editor for Review Geek, where he covers breaking stories and manages the news team. He joined Life Savvy Media as a freelance writer in 2018 and has experience in a number of topics, including mobile hardware, audio, and IoT. Read Full Bio »