Junglewise Threat Intelligence

CVE-2026-5768: Fourth Frontier Frontier X2 Missing Authentication in BLE GATT Characteristics

CVE-2026-5768 · Severity: high · CVSS 8.8 · Published 2026-05-29

Executive brief

The Fourth Frontier Frontier X2 is a wearable heart monitoring device used for tracking health telemetry. A security vulnerability allows unauthorized individuals within Bluetooth range to take control of the device or feed fake health data to the mobile app. This could lead to the manipulation of medical readings, such as heart rate and breathing rate, potentially resulting in incorrect health assessments or patient harm.

Technical details

The Frontier X2 device fails to enforce pairing authentication or authorization for critical GATT characteristics. An attacker within BLE range can perform unauthenticated read/write operations to control device functions (e.g., starting/stopping activities, triggering vibrations) or cause a denial-of-service. Furthermore, the Frontier X mobile application lacks proper BLE device authentication, enabling an attacker to impersonate a legitimate device by cloning BLE advertisements. This allows for the injection of fabricated health telemetry, including heart rate, breathing rate, and strain data, into the user's mobile application. The vulnerability is classified as Missing Authentication for Critical Function (CWE-306).

Affected products

  • Fourth Frontier Frontier X2 All versions
  • Fourth Frontier Frontier X Android application < v15.0.0
  • Fourth Frontier Frontier X iOS application < v25.0.0

Timeline

  • 2026-05-28: advisory: CISA ICS Medical Advisory ICSMA-26-148-01 released
  • 2026-05-29: disclosed: CVE-2026-5768 published to NVD

References