Description
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access via unauthenticated BLE
Action: Update firmware
AI Analysis

Impact

Bluetooth Low Energy (BLE) connections to the TCH QRing R20_B006 smart ring are possible without any pairing or authentication because the exposed Nordic UART Service does not enforce client authentication or command authorization. This flaw permits any nearby attacker to connect, read the battery level, enable live heart rate monitoring, and retrieve stored heart rate and blood oxygen data. The vulnerability enables unauthorized disclosure of personal health information, violating confidentiality, and is identified as CWE‑306, an authentication weakness.

Affected Systems

The flaw exists in the TCH QRing R20_B006 ring model, running firmware version RT09R20_1.00.00_250318. Any device manufactured with this firmware and exposing the Nordic UART Service is affected. No other versions or products were listed, so the risk is limited to systems that have the exact firmware identified.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score of < 1% indicates that the current probability of exploitation in the wild is low, yet the lack of any official KEV listing does not preclude future exploitation once the pattern is discovered. Attackers only need to be within typical BLE range and no special credentials; the vector is local, physical proximity, and exploits do not require user interaction or further configuration.

Generated by OpenCVE AI on September 18, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware from TCH that disables the unsecured Nordic UART Service or requires authentication before granting BLE access.
  • Turn off Bluetooth or lock the ring when not in use to prevent unintended nearby connections.
  • Physically secure the device so that only trusted individuals have proximity to the ring, reducing the chance of an attacker within BLE range.

Generated by OpenCVE AI on September 18, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tch
Tch qring
Vendors & Products Tch
Tch qring

Wed, 16 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
Title TCH QRing R20_B006 Unauthenticated BLE Access
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:00:13.386Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89034

cve-icon Vulnrichment

Updated: 2026-09-19T02:00:07.441Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:27.613

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-89034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:00Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function