CVE-2021-35954

fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fastrack:reflex_2.0_firmware:90.89:*:*:*:*:*:*:*
cpe:2.3:h:fastrack:reflex_2.0:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:12

Type Values Removed Values Added
References () https://payatu.com/advisory/dumping-and-re-flashing-firmware-fastrack-reflex - Third Party Advisory () https://payatu.com/advisory/dumping-and-re-flashing-firmware-fastrack-reflex - Third Party Advisory
References () https://www.fastrack.in/shop/watch-smart-wearables-reflex-2 - Broken Link, Product () https://www.fastrack.in/shop/watch-smart-wearables-reflex-2 - Broken Link, Product

Information

Published : 2022-12-26 06:15

Updated : 2025-04-14 19:15


NVD link : CVE-2021-35954

Mitre link : CVE-2021-35954

CVE.ORG link : CVE-2021-35954


JSON object : View

Products Affected

fastrack

  • reflex_2.0
  • reflex_2.0_firmware