CVE-2019-12780
CVE-2019-12780
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →