Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-37271: Fire-Boltt Smartwatch Firmware: Unauthenticated Access to Device Functions

CVE-2026-37271
Summary

Fire-Boltt smartwatches with certain firmware versions may allow unauthorized access to their functions. This means that someone with the right tools and information could potentially control or access sensitive features on the device. To protect your smartwatch, update to the latest firmware version as soon as possible.

Original title
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session...
Original description
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.
Vulnerability type
CWE-287 Improper Authentication
Published: 7 Jul 2026 · Updated: 23 Jul 2026 · First seen: 7 Jul 2026