CVE-2019-17532: High severity belkin wemo switch firmware vulnerability
An issue was discovered on Belkin Wemo Switch 28B WW2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-17532.
What is the severity of CVE-2019-17532?
The severity of CVE-2019-17532 is high with a score of 7.5.
How does CVE-2019-17532 affect Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices?
CVE-2019-17532 allows remote attackers to cause a denial of service (persistent rules-processing outage) on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI.
Is there a fix available for CVE-2019-17532?
At the time of writing, there is no known fix or patch available for CVE-2019-17532. It is recommended to apply any security updates provided by the vendor.