Executive brief
The Fire-Boltt FB BGS001 smartwatch is vulnerable to an authentication flaw in its Bluetooth communication. An attacker within Bluetooth range can capture and replay wireless signals to trigger functions on the watch without the owner's permission. This could allow an unauthorized person to control device features or interact with the watch remotely.
Technical details
The Fire-Boltt Smartwatch FB BGS001 (firmware MOY-JS14-2.0.4) suffers from improper authentication in its Bluetooth Low Energy (BLE) implementation. The device accepts GATT Write Request commands without sufficient authentication or session validation. An attacker within physical proximity (Bluetooth range) can capture BLE packets and replay them to the device. This allows the attacker to trigger smartwatch functionality without a legitimate authenticated session. The vulnerability is rooted in the lack of replay protection and weak session management during GATT operations.
Affected products
- Fire-Boltt Smartwatch FB BGS001 MOY-JS14-2.0.4
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory