PT-2026-25613 · I Sens · Smartlog App

·

CVE-2026-4216

·

Published

2026-03-16

·

Updated

2026-03-17

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions i-SENS SmartLog App versions up to 2.6.8
Description A weakness exists in the i-SENS SmartLog App on Android, affecting an unknown function within the air.SmartLog.android component. This issue results in the presence of hard-coded credentials. The attack is limited to local execution. The exploit is publicly available. The affected function is related to a developer mode used for Bluetooth pairing between a blood glucose meter and the SmartLog application, intended for device integration and testing.
Recommendations Versions up to 2.6.8 should be updated when a future application update is released that either removes the developer mode function or restricts access to it.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4216

Affected Products

Smartlog App