First published: Mon Jun 10 2019(Updated: )
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin Crock-pot Smart Slow Cooker With Wemo Firmware | ||
Belkin Crock-pot Smart Slow Cooker With Wemo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12780 is a vulnerability found in the Belkin Wemo Enabled Crock-Pot that allows command injection through the Wemo UPnP API.
CVE-2019-12780 has a severity rating of 9.8, which is considered critical.
CVE-2019-12780 allows an attacker to execute commands without authentication by sending a simple POST request to the /upnp/control/basicevent1 endpoint.
The Belkin Crock-pot Smart Slow Cooker with Wemo Firmware is affected by CVE-2019-12780.
No, the Belkin Crock-pot Smart Slow Cooker with Wemo is not vulnerable to CVE-2019-12780.
To fix CVE-2019-12780, it is recommended to update the firmware of the Belkin Wemo Enabled Crock-Pot to a version that addresses the vulnerability.