Executive brief
The Apollo Pharmacy Blood Glucose Monitoring System (APG-01 BT) is a medical device used by patients to track blood sugar levels. A vulnerability in its Bluetooth communication allows an attacker within physical range to block the device's only available connection slot. This prevents the patient or their mobile application from connecting to the device, effectively causing a denial-of-service that disrupts health monitoring operations.
Technical details
The Apollo Pharmacy Blood Glucose Monitoring System (Model No. APG-01 BT) version 0x0110_v1.1.0 contains a missing authorization vulnerability (CWE-862) in its Bluetooth Low Energy (BLE) implementation. The device supports only a single active BLE connection at a time. An attacker within BLE range can establish a connection to this slot without authentication, thereby 'monopolizing' the connection and preventing legitimate applications or users from pairing or syncing data. This results in a permanent denial-of-service condition as long as the attacker maintains the connection. No patch is currently available as the vendor did not respond to coordination efforts; CISA recommends following general Bluetooth security best practices.
Affected products
- Apollo Pharmacy Blood Glucose Monitoring System (Model No. APG-01 BT) 0x0110_v1.1.0
Timeline
- 2026-06-18: advisory: Initial publication by CISA (ICSMA-26-169-01)
- 2026-06-19: disclosed: CVE published to NVD