Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.
References
Configurations
No configuration.
History
10 Dec 2025, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-10 13:16
Updated : 2025-12-12 15:18
NVD link : CVE-2024-2104
Mitre link : CVE-2024-2104
CVE.ORG link : CVE-2024-2104
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
