Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-5768 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-306Missing Authentication for Critical Function[email protected]

Affected Products

ProductVersions
Fourth Frontier Frontier X2
< 15.0.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Mitigation:low effort

    Connect the Frontier X2 device using the Frontier X app before starting any activity, as it can only connect to one app at a time.

  • Mitigation:low efforthttps://fourthfrontier.com/pages/contact-us

    Contact Fourth Frontier for assistance regarding this vulnerability.

Fourth Frontier Frontier X
< 25.0.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Mitigation:low effort

    Connect the Frontier X device using the Frontier X app before starting any activity, as it can only connect to one app at a time.

  • Mitigation:low efforthttps://fourthfrontier.com/pages/contact-us

    Contact Fourth Frontier for assistance regarding this vulnerability.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-5768
NVD Published Date:
May 29, 2026
NVD Last Modified:
Jul 22, 2026
Source:
[email protected]