Impact
Bluetooth Low Energy (BLE) connections to the TCH QRing R20_B006 smart ring are possible without any pairing or authentication because the exposed Nordic UART Service does not enforce client authentication or command authorization. This flaw permits any nearby attacker to connect, read the battery level, enable live heart rate monitoring, and retrieve stored heart rate and blood oxygen data. The vulnerability enables unauthorized disclosure of personal health information, violating confidentiality, and is identified as CWE‑306, an authentication weakness.
Affected Systems
The flaw exists in the TCH QRing R20_B006 ring model, running firmware version RT09R20_1.00.00_250318. Any device manufactured with this firmware and exposing the Nordic UART Service is affected. No other versions or products were listed, so the risk is limited to systems that have the exact firmware identified.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score of < 1% indicates that the current probability of exploitation in the wild is low, yet the lack of any official KEV listing does not preclude future exploitation once the pattern is discovered. Attackers only need to be within typical BLE range and no special credentials; the vector is local, physical proximity, and exploits do not require user interaction or further configuration.
OpenCVE Enrichment