Skip to main content

Internet-connected Mr. Coffee machines have security vulnerability, McAfee says

Mr. Coffee Smart Coffeemaker
Image used with permission by copyright holder

It may sound scary, but while you’re making yourself a cup of coffee, a hacker just may be brewing up an attack. According to security firm McAfee, an internet-connected coffee maker produced by Mr. Coffee and Wemo suffers from a security vulnerability that could let a malcious actor intercept traffic from the device and even schedule the machine to make coffee without the owner’s permission.

The affected device is the Mr. Coffee Coffee Maker with Wemo, first introduced back in 2014. The issue stems from the connectivity provided by Wemo. According to McAfee, Wemo devices communicate with a connected Wemo smartphone app, and can transfer date in two ways: Remotely via the internet or locally, bysending the information directly to the Wemo application. The vulnerabilty occurs when the communication is taking place locally.

McAfee researchers discovered it is possible to intercept transmissions made between the Mr. Coffee Coffee Maker with Wemo and the connected Wemo app. This can occur because the data is transferred in plaintext with no additional encryption or protection to prevent the information from being viewed by a malicious third party. By viewing that information, an attacker can see different data that is bouncing between the device and the Wemo app, including the brew schedule — times that the device owner has set up the machine to automatically brew a new pot of coffee.

With access to the communication between the coffee maker and app, a hacker could theoretically start inserting their own commands and pushing them to the device. That means an attacker could schedule the coffee maker to turn on without the permission or knowledge of the owner. McAfee pointed out that there is no validation on the source of a scheduled brew, so there is nothing to prevent the action from going forward even though it’s from an illegitimate source.

“Cybercriminals are relentless, and as long as we continue to connect devices to the internet, they will continue to search for ways to exploit them,” Raj Samani, McAfee fellow and chief scientist, said in a statement. “Vulnerability disclosures can be frightening for both the consumers using connected devices and the organizations that create them, however, the process is an essential component of creating a safer future. Cybersecurity researchers, businesses, and consumers working together to expose and eliminate these vulnerabilities keeps us all a step ahead of the bad guys.”

It’s worth noting that these types of attacks would have to be targeted efforts. A hacker would have to be connected to the same network that the vulnerable coffee maker is on. It also requires the coffee maker to be communicating locally rather than remotely, when remote access is the default setting for the machine. When conacted, Wemo parent company Belkin told Digital Trends it issued an advisory for the issue in August and offered a firmware update to address the issue on January 8, 2019.

Editors' Recommendations

AJ Dellinger
AJ Dellinger is a freelance reporter from Madison, Wisconsin with an affinity for all things tech. He has been published by…
If you use a VPN, don’t skip this important Windows 11 update
Microsoft Surface Laptop Go 3 rear view showing lid and logo.

It's not you; Windows is causing the issues this time. If the VPN on your Windows 11 or Windows 10 computer is having a hard time connecting, it is likely because of Microsoft's April security updates for Windows 11 (KB5036893 for) and Windows 10 (KB5036892), which have been reported to be the cause of the problems.

But there's good news. According to Microsoft, a patch is now available to fix the VPN problems users are experiencing.

Read more
This new Google Sheets feature is going to save so much time
Google Sheets is open in the Safari browser on a MacBook Air.

After Google I/O 2024, Google continues to roll out features that bolster its productivity apps -- this time, specifically with Google Sheets. As picked up by The Verge, Google has announced a much simpler way to generate easily formatted tables in the Sheets app. This new Sheets feature has been around for many years in Excel and has recently reached Google. Better late than never.

The option is called Convert to table, and you can use it by opening a Sheets document and clicking Format > Convert to table when the option reaches you later this month or early next. With this new option, Google aims for a more Excel-type experience by adding filters for each column. The rows also get visual separators, saving you time by not having to select the rows manually to turn them gray. The Convert to table feature also brings filters and column types and makes the drop-down menu creation easier.

Read more
The iPhone 16 Pro Max may get a very important battery upgrade
An iPhone 15 Pro Max laying face-down outside, showing the Natural Titanium color.

iPhone 16 dummy models Sonny Dickson / X

The iPhone 16 still has many months to go before its anticipated announcement in the fall, but we’ve already gotten a slew of rumors, leaks, and speculation about its specs and capabilities. One of the latest rumors about the iPhone 16 Pro Max comes from analyst Ming-Chi Kuo and it regards a new battery Apple is putting into the device.

Read more