Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-37271

CVE-2026-37271: Fire-Boltt Smartwatch Auth Bypass Flaw

CVE-2026-37271 is an authentication bypass vulnerability in Fire-Boltt Smartwatch FB BGS001 that allows replay attacks via BLE. This article covers the technical details, affected firmware versions, and mitigation strategies.

Published:

CVE-2026-37271 Overview

CVE-2026-37271 is an authentication vulnerability affecting the Fire-Boltt Smartwatch FB BGS001 running firmware MOY-JS14-2.0.4. The device processes Bluetooth Low Energy (BLE) GATT Write Request commands without adequate authentication or session validation. An attacker within BLE radio range can capture legitimate packets and replay them to trigger smartwatch functionality. The flaw is classified under [CWE-287: Improper Authentication].

Critical Impact

Attackers within BLE range can replay captured GATT Write commands to control smartwatch functions without valid credentials or session state.

Affected Products

  • Fire-Boltt Smartwatch FB BGS001
  • Firmware version MOY-JS14-2.0.4
  • BLE GATT service interface on the device

Discovery Timeline

  • 2026-07-07 - CVE-2026-37271 published to NVD
  • 2026-07-09 - Last updated in NVD database

Technical Details for CVE-2026-37271

Vulnerability Analysis

The Fire-Boltt FB BGS001 smartwatch exposes GATT (Generic Attribute Profile) characteristics that accept Write Request commands over BLE. The firmware does not enforce a strong pairing or session-binding mechanism on these characteristics. Because BLE traffic between the smartwatch and its companion mobile application is not sufficiently protected, an attacker with a BLE sniffer can capture command frames during normal use.

Once captured, the same frames can be transmitted from an attacker-controlled BLE device. The smartwatch accepts the replayed packets as valid, because it does not validate freshness through nonces, counters, or authenticated session keys. This allows unauthorized invocation of device features exposed through GATT.

The issue is a BLE authentication and replay-protection failure typical of low-cost consumer wearables that rely on "Just Works" pairing or unauthenticated GATT characteristics.

Root Cause

The root cause is missing authentication and missing anti-replay protection on GATT Write Request handlers in firmware MOY-JS14-2.0.4. The device treats any well-formed GATT write as authorized without verifying the source or session state of the request.

Attack Vector

The attack is executed within BLE proximity. The adversary observes and records BLE traffic while the watch is being used, then retransmits selected packets from a nearby radio to trigger smartwatch functionality. No user interaction on the victim device is required at the time of the replay.

No verified proof-of-concept code is published. Technical details are available in the CVE-2026-37271 research repository and the associated PDF.

Detection Methods for CVE-2026-37271

Indicators of Compromise

  • Unexpected activation of smartwatch functions when the paired phone is out of range or disconnected.
  • Repeated identical BLE GATT Write frames observed on the device's advertised service UUIDs.
  • Presence of unknown BLE central devices connecting to the smartwatch's GATT server.

Detection Strategies

  • Capture BLE traffic near test devices using an nRF Sniffer or Ubertooth and inspect for duplicate GATT Write payloads with identical byte sequences.
  • Correlate companion application logs with BLE link events to identify commands executed without a matching user action.
  • Monitor for connections from BLE MAC addresses that are not the paired handset.

Monitoring Recommendations

  • Track BLE connection attempts and GATT write activity in enterprise environments where wearables are permitted.
  • Alert on BLE devices advertising outside expected working hours or in restricted areas.
  • Include IoT and wearable telemetry in centralized security monitoring where feasible.

How to Mitigate CVE-2026-37271

Immediate Actions Required

  • Disable BLE on the Fire-Boltt FB BGS001 when it is not actively in use with the paired companion application.
  • Restrict use of the affected smartwatch in sensitive physical environments until a firmware update is issued.
  • Inventory devices running firmware MOY-JS14-2.0.4 and flag them for follow-up.

Patch Information

No vendor patch or fixed firmware version has been published in the referenced advisory material at the time of NVD publication. Consult the CVE-2026-37271 research repository and the vendor's official channels for updated firmware announcements.

Workarounds

  • Keep the smartwatch physically close to the paired phone to reduce the opportunity for third-party BLE capture.
  • Avoid using the device in high-density public environments where BLE sniffing is more feasible.
  • Where organizational policy allows, prohibit connection of consumer wearables running unpatched firmware to corporate mobile devices.
bash
# Example: list nearby BLE devices to identify unexpected peers on Linux
sudo hcitool lescan
# Inspect GATT services exposed by a target device
gatttool -b <DEVICE_MAC> -I

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.