๐Ÿ” CVE Alert

CVE-2026-5768

HIGH 8.8

Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical Function

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.

CWE CWE-306
Vendor fourth frontier
Product frontier x android application
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for fourth frontier frontier x android application

Be the first to know when new high vulnerabilities affecting fourth frontier frontier x android application are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Fourth Frontier / Frontier X Android application
0 < 15.0.0
Fourth Frontier / Frontier X IOS application
0 < 25.0.0
Fourth Frontier / Frontier X2
All versions

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fourthfrontier.com: https://fourthfrontier.com/pages/contact-us cisa.gov: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-148-01 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-148-01.json

Credits

Shakir Zari and Jerin Sunny reported this vulnerability to CISA.