May 17, 2023, 6:34 p.m. | /u/wehivo9

cybersecurity www.reddit.com

Just read about the vulnerability found in the Wemo Mini Smart Plug V2, a widely used IoT device. IMO this is pretty concerning as these devices are not only used in homes, but also in business environments.
To keep it brief, the vulnerability, designated CVE-2023-27217, is a buffer overflow that allows remote command injection. This issue stems from the device's 'FriendlyName' feature, which lets users rename the device. The problem arises when the name exceeds 30 characters, causing a buffer …

buffer buffer overflow buffer overflow vulnerability business critical cve cybersecurity device devices environments homes iot iot device overflow smart vulnerability wemo wemo mini smart plug v2

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Cyber Incident Manager 3

@ ARSIEM | Pensacola, FL

On-Site Environmental Technician II - Industrial Wastewater Plant Operator and Compliance Inspector

@ AECOM | Billings, MT, United States

Sr Security Analyst

@ Everbridge | Bengaluru