Impact
The Fire‑Boltt smartwatch model FB BGS001 runs firmware MOY‑JS14‑2.0.4 and mishandles GATT Write Request commands, accepting them without verifying the source or ensuring a valid session. This Improper Authentication flaw (CWE‑287) lets an attacker capture a legitimate Bluetooth Low Energy traffic stream and replay the packets from a nearby device, forcing the watch to perform functions such as changing settings, triggering alarms, or secreting data. Based on the description, the likely attack vector requires the attacker to be within Bluetooth range to intercept and replay traffic, thereby granting remote control over the device’s features without the owner’s awareness.
Affected Systems
Only the Fire‑Boltt smartwatch FB BGS001 running firmware version MOY‑JS14‑2.0.4 is listed as affected; no other models, firmware revisions, or vendors are currently reported.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating high severity, while its EPSS score is less than 1%, suggesting a low current exploitation probability. It is not present in the CISA KEV catalog. The technical barrier to exploitation is low because the attacker needs only proximity to the device and the ability to capture BLE traffic, which are typically easy to achieve in retail or personal environments. Consequently, the risk to confidentiality, integrity, and availability remains significant for any user who does not apply the appropriate mitigation.
OpenCVE Enrichment