IoT & Hardware
Hardware / Firmware Exposure
Authentication & Access Bypass
Lack of Bluetooth LE pairing and access control in Fastrack reflex 2.0 activity tracker
Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value…
.png)
Overview
Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch
It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value modifying the time date and month changes. An attacker can change the time date and month.
Vulnerability details
Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value modifying the time date and month changes.
Disclosure timeline
2020-11-17 reported to the vendor
2021-06-30 No response from the vendor and moving forward to public disclosure.
References
Credits
Shakir Zari
















