Vulnerability Description
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-37271/CVE-2026-37271.pdf
- https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2026-37271
FAQ
What is CVE-2026-37271?
CVE-2026-37271 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session va...
How severe is CVE-2026-37271?
CVE-2026-37271 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-37271?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.