CVE-2019-12780: OS Command Injection
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12780?
CVE-2019-12780 is a vulnerability found in the Belkin Wemo Enabled Crock-Pot that allows command injection through the Wemo UPnP API.
How severe is CVE-2019-12780?
CVE-2019-12780 has a severity rating of 9.8, which is considered critical.
How does CVE-2019-12780 work?
CVE-2019-12780 allows an attacker to execute commands without authentication by sending a simple POST request to the /upnp/control/basicevent1 endpoint.
Which software is affected by CVE-2019-12780?
The Belkin Crock-pot Smart Slow Cooker with Wemo Firmware is affected by CVE-2019-12780.
Is the Belkin Crock-pot Smart Slow Cooker with Wemo vulnerable to CVE-2019-12780?
No, the Belkin Crock-pot Smart Slow Cooker with Wemo is not vulnerable to CVE-2019-12780.
How can I fix CVE-2019-12780?
To fix CVE-2019-12780, it is recommended to update the firmware of the Belkin Wemo Enabled Crock-Pot to a version that addresses the vulnerability.