Fireboltt · Fb Bgs001 · CVE-2026-37271
**Name of the Vulnerable Software and Affected Versions**
Fire-Boltt Smartwatch FB BGS001 version MOY-JS14-2.0.4
**Description**
Improper authentication allows the device to accept GATT Write Request commands without sufficient authentication or strong session validation. This enables a nearby device to replay previously captured BLE (Bluetooth Low Energy) packets to trigger functionality on the smartwatch.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.