Skip to main content
Mallory
CriticalPublic exploit

Unauthenticated Command Injection in Belkin Wemo Enabled Crock-Pot UPnP API

IdentifiersCVE-2019-12780CWE-78· Improper Neutralization of Special…

CVE-2019-12780 is a command injection vulnerability in the Belkin Wemo Enabled Crock-Pot UPnP API. The flaw is exposed through the SetSmartDevInfo action, where the SmartDevURL argument is not properly sanitized before being used by the device. An attacker can send a crafted POST request to /upnp/control/basicevent1 and inject operating-system commands via SmartDevURL. According to the provided content, exploitation does not require authentication.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary command execution on the vulnerable device without authentication. This can enable full compromise of the appliance’s underlying system, including modification of device behavior, execution of attacker-supplied payloads, persistence, and potential use of the device as a foothold for further activity on the local network.

Mitigation

If you can’t patch tonight, do this now.

Until patched, restrict network access to the device’s UPnP control interface, especially /upnp/control/basicevent1, to trusted management hosts only. Do not expose the device to untrusted networks. Segment IoT devices onto isolated VLANs or dedicated networks, apply ACLs or firewall rules to limit lateral access, and monitor for unexpected POST requests to the UPnP endpoint or anomalous command execution behavior. If the device is not required, disconnect it from the network.

Remediation

Patch, then assume compromise.

Apply the vendor-provided firmware update or patch that corrects input handling in the Wemo UPnP API, specifically the processing of the SmartDevURL parameter in SetSmartDevInfo. If a fixed firmware version is available from Belkin/Wemo, upgrade affected Crock-Pot devices to that version. Replace unsupported devices that no longer receive security updates.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
BelkinCrock-Pot Smart Slow Cooker With Wemo Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.