{"api_version":"1","generated_at":"2026-07-23T06:57:08+00:00","cve":"CVE-2013-6949","urls":{"html":"https://cve.report/CVE-2013-6949","api":"https://cve.report/api/cve/CVE-2013-6949.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-6949","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-6949"},"summary":{"title":"CVE-2013-6949","description":"The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.","state":"PUBLISHED","assigner":"certcc","published_at":"2014-02-22 21:55:09","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf","name":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/656302","name":"http://www.kb.cert.org/vuls/id/656302","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Vulnerability Note VU#656302 - Belkin Wemo Home Automation devices contain multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-6949","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6949","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"6949","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"belkin","cpe5":"wemo_home_automation_firmware","cpe6":"2769","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"6949","cve":"CVE-2013-6949","epss":"0.018660000","percentile":"0.770850000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T17:53:45.393Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf"},{"name":"VU#656302","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/656302"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-02-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-02-24T05:57:03.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf"},{"name":"VU#656302","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/656302"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2013-6949","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf","refsource":"MISC","url":"http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf"},{"name":"VU#656302","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/656302"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2013-6949","datePublished":"2014-02-22T21:00:00.000Z","dateReserved":"2013-12-04T00:00:00.000Z","dateUpdated":"2024-08-06T17:53:45.393Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-02-22 21:55:09","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:belkin:wemo_home_automation_firmware:2769:*:*:*:*:*:*:*","matchCriteriaId":"28ACACEF-ADE2-4A54-8F6D-281167EA4A0C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"6949","Ordinal":"1","Title":"CVE-2013-6949","CVE":"CVE-2013-6949","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"6949","Ordinal":"1","NoteData":"The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.","Type":"Description","Title":"CVE-2013-6949"},{"CveYear":"2013","CveId":"6949","Ordinal":"2","NoteData":"2014-02-22","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"6949","Ordinal":"3","NoteData":"2014-02-24","Type":"Other","Title":"Modified"}]}}}