CVE-2026-5768 Details
Description
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.
A vulnerability exists in the Fourth Frontier Frontier X2 device, allowing unauthenticated Bluetooth Low Energy (BLE) read/write access to critical GATT characteristics. This flaw bypasses pairing authentication and authorization, enabling attackers within BLE range to gain unauthorized control over device functions. Exploitation can involve starting or stopping activities, triggering vibrations, creating denial-of-service conditions, and fuzzing characteristic values to provoke unexpected behavior. Furthermore, the associated Frontier X mobile application lacks adequate BLE device authentication. This deficiency permits attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and presenting expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry, such as breathing rate, heart rate, strain, and other health-related data, into the mobile application.
Fourth Frontier is aware of the vulnerability and is working on a fix. Users are encouraged to contact Fourth Frontier directly for assistance. The Frontier X/X2 devices can connect to only one app at a time; users should first connect the device using the Frontier X app and then start the activity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fourth Frontier Frontier X2 | < 15.0.0 (semver) |
CPE
Remediation
| |
| Fourth Frontier Frontier X | < 25.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | [email protected] |
Volerion