PT-2026-44968 · Frontier · Frontier+1

·

CVE-2026-5768

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontier X2 (affected versions not specified) Frontier X mobile application (affected versions not specified)
Description The Frontier X2 device permits unauthenticated Bluetooth Low Energy (BLE) read and write access to critical Generic Attribute Profile (GATT) characteristics because it does not enforce pairing authentication or authorization. This allows an attacker within BLE range to gain unauthorized control over device functions, such as starting or stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Furthermore, the Frontier X mobile application does not properly authenticate BLE devices, enabling attackers to impersonate a legitimate Frontier X2 device. By cloning BLE advertisements and exposing the expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry, including heart rate, breathing rate, strain, and other health-related data, into the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5768

Affected Products

Frontier
Frontier X2