LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-5768

Published
CVSS8.8
Severityhigh
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipula

References

← Back to the CVE Tracker

Our coverage of CVE-2026-5768

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-5768.