CVE-2026-37271 Details
Description
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.
A vulnerability exists in the Fire-Boltt Smartwatch FB BGS001 running firmware version MOY-JS14-2.0.4. The issue stems from improper authentication, as the device accepts GATT Write Request commands without adequate authentication or robust session validation. This flaw enables the replay of previously captured Bluetooth Low Energy (BLE) packets from a nearby device, potentially triggering certain functionalities on the smartwatch without a valid authenticated session.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-37271/CVE-2026-37271.pdf | [email protected] | Partial Content |
| https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2026-37271 | [email protected] | AdvisoryPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Fire-Boltt Smartwatch FB BGS001 | MOY-JS14-2.0.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | New CVE Received | [email protected] |
Volerion