Executive brief
SafeLine SL6 and SL6+ devices are communication gateways used in elevator emergency intercom systems to connect trapped passengers with emergency services. A security flaw allows an attacker within wireless range to bypass the PIN protection on the device's Bluetooth interface and gain administrative control. This could allow an attacker to change emergency contact numbers, potentially preventing help from being summoned during an elevator emergency or hijacking the communication line.
Technical details
An authentication bypass vulnerability (CWE-305) exists in the Bluetooth Low Energy (BLE) configuration interface of SafeLine SL6 and SL6+ devices. The flaw allows an attacker within wireless range to bypass the PIN-based authentication mechanism with a small number of requests, gaining full access to the device's configuration service. This service is typically used via the SafeLine LYNX mobile app to manage critical settings like 4G VoLTE emergency dial numbers. The vulnerability is present when the 'Auto Enable BLE' setting is active. Firmware version 4.97 mitigates this by removing PIN authentication entirely and restricting BLE access to a short window following a device reboot.
Affected products
- SafeLine SafeLine SL6/SL6+ 4.82 to 4.96
Timeline
- 2025-03-28: other: Vulnerability discovered
- 2025-04-14: other: Initial contact with vendor
- 2025-12-19: patched: Vendor released firmware version 4.97
- 2026-06-19: advisory: Advisory released by SCHUTZWERK
- 2026-06-22: disclosed: CVE published to NVD