Description
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fire‑Boltt smartwatch model FB BGS001 runs firmware MOY‑JS14‑2.0.4 and mishandles GATT Write Request commands, accepting them without verifying the source or ensuring a valid session. This Improper Authentication flaw (CWE‑287) lets an attacker capture a legitimate Bluetooth Low Energy traffic stream and replay the packets from a nearby device, forcing the watch to perform functions such as changing settings, triggering alarms, or secreting data. Based on the description, the likely attack vector requires the attacker to be within Bluetooth range to intercept and replay traffic, thereby granting remote control over the device’s features without the owner’s awareness.

Affected Systems

Only the Fire‑Boltt smartwatch FB BGS001 running firmware version MOY‑JS14‑2.0.4 is listed as affected; no other models, firmware revisions, or vendors are currently reported.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating high severity, while its EPSS score is less than 1%, suggesting a low current exploitation probability. It is not present in the CISA KEV catalog. The technical barrier to exploitation is low because the attacker needs only proximity to the device and the ability to capture BLE traffic, which are typically easy to achieve in retail or personal environments. Consequently, the risk to confidentiality, integrity, and availability remains significant for any user who does not apply the appropriate mitigation.

Generated by OpenCVE AI on July 23, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest firmware upgrade for the FB BGS001 model when it becomes available.
  • Configure the smartwatch to enforce secure pairing and to require authentication before accepting any GATT write commands, ensuring that only authorized devices can issue control actions.
  • If a firmware update cannot be applied, disable BLE advertising or isolate the watch from untrusted Bluetooth traffic by restricting proximity to known devices.

Generated by OpenCVE AI on July 23, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Allowing BLE Replay Attack

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Allowing BLE Replay Attack

Mon, 13 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized BLE Replay Enables Remote Control on Fire‑Boltt Smartwatch

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized BLE Replay Enables Remote Control on Fire‑Boltt Smartwatch

Sat, 11 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Enables BLE Replay Attack

Fri, 10 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Enables BLE Replay Attack

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Firmware Allows BLE Replay Attacks
Weaknesses CWE-613

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
References

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Fire‑Boltt Smartwatch Firmware Allows BLE Replay Attacks
Weaknesses CWE-287
CWE-613

Tue, 07 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T14:43:11.606Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37271

cve-icon Vulnrichment

Updated: 2026-07-09T14:04:52.671Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:15:03Z

Weaknesses