HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2013-6948

CVSS 7.8v2.0pub. 2014-02-22upd. 2026-04-29

The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
  • Belkin Wemo Home Automation Firmware

    APP
    Belkin
    2769
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2013-6949HIGH9.3same product

The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which ...

CVE-2013-6950HIGH7.8same product

The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows ...

CVE-2013-6951HIGH7.1same product

The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public...

CVE-2013-6952HIGH10.0same product

The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote...

CVE-2023-27217CRITICAL9.8PL ✓same vendor

Stack-based buffer overflow w Belkin Smart Outlet V2 F7C063 via UPnP