IoT & Hardware
Hardware / Firmware Exposure
Unauthenticated Firmware Update in Fastrack Reflex 2.0 Activity Tracker
Unauthenticated Firmware Update It was identified on analyzing the Bluetooth LE Characteristics of the device that it is using Nordic DFU 0.1 and has no signature verification for OTA Firmware…
.png)
Overview
Unauthenticated Firmware Update
It was identified on analyzing the Bluetooth LE Characteristics of the device that it is using Nordic DFU 0.1 and has no signature verification for OTA Firmware Update. An attacker can send a malicious firmware and brick the device
Vulnerability details
Unauthenticated Firmware Update It was identified on analyzing the Bluetooth LE Characteristics of the device that it is using Nordic DFU 0.1 and has no signature verification for OTA Firmware Update.
Disclosure timeline
2020-11-17 reported to the vendor
2021-06-30 CVE was assigned and reserved by MITRE
2022-04-07 No response from the vendor and moving forward to Public disclosure.
References
Credits
Shakir zari
















