CVE-2021-35951

fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fastrack:reflex_2.0_firmware:90.89:*:*:*:*:*:*:*
cpe:2.3:h:fastrack:reflex_2.0:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:12

Type Values Removed Values Added
References () https://payatu.com/advisory/fastrack-reflex-unauthenticated-firmware-update - Third Party Advisory () https://payatu.com/advisory/fastrack-reflex-unauthenticated-firmware-update - Third Party Advisory
References () https://www.fastrack.in/shop/watch-smart-wearables-reflex-2 - Permissions Required () https://www.fastrack.in/shop/watch-smart-wearables-reflex-2 - Permissions Required

Information

Published : 2022-12-26 06:15

Updated : 2025-04-14 19:15


NVD link : CVE-2021-35951

Mitre link : CVE-2021-35951

CVE.ORG link : CVE-2021-35951


JSON object : View

Products Affected

fastrack

  • reflex_2.0
  • reflex_2.0_firmware