CVE-2013-6951 describes a critical vulnerability in Belkin WeMo Home Automation firmware versions prior to 3949. The flaw stems from the firmware's failure to maintain a trusted list of Certification Authority public keys, enabling man-in-the-middle attackers to spoof SSL servers using any arbitrary X.509 certificate. This vulnerability has a CVSS score of 7.1, indicating high severity with network-based attacks and medium complexity, potentially leading to significant integrity impacts. There is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2769CPE matchmatch criteria | cpe:2.3:a:belkin:wemo_home_automation_firmware:2769:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:C/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.