Vulnerabilities for Over Half a Million Belkin WeMo Users
ioactive.com
ioactive.com
My real worry here is that people are selling the devices short. "So what, someone can turn my lights off?". Each one of these devices can act as a WAP - they do so for the initial setup (you join the device's wap with your phone and initiate config from there). Each one of these devices has your network credentials - they have to, to join your LAN.
Being able to sign & push your own firmware updates makes this a troubling combination. It's well within each and every one of these "fire and forget" devices to sit there broadcasting your network credentials.
Asking the users to solve this is hugely ineffective. If you block outbound traffic, you don't receive firmware updates, and lose half the featureset. If you isolate them onto a 'guest lan' to prevent them having useful data to leak, then you lose the other half of the featureset.
The real failure here is bad key hygiene, a ball which is firmly in Belkin's court - and they're refusing to even acknowledge it as an issue.