CVE-2013-6952: Critical severity Belkin WeMo Home Automation firmware vulnerability
The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware updates and execute arbitrary code via crafted signed data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Belkin WeMo Home Automation firmwareto a version that resolves this vulnerability.Fixed in 3949
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6952?
CVE-2013-6952 is classified as a high severity vulnerability due to the risk of remote code execution.
How do I fix CVE-2013-6952?
To mitigate CVE-2013-6952, upgrade the Belkin WeMo Home Automation firmware to version 3949 or later.
What are the potential exploits of CVE-2013-6952?
CVE-2013-6952 allows attackers to spoof firmware updates and execute arbitrary code on vulnerable devices.
Which devices are affected by CVE-2013-6952?
CVE-2013-6952 affects Belkin WeMo Home Automation firmware version 2769 and earlier.
Is CVE-2013-6952 a local or remote vulnerability?
CVE-2013-6952 is a remote vulnerability, allowing attackers to exploit it over a network.