PT-2026-94092 · Tch · Qring Smart Ring R20 B006
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TCH QRing smart ring model R20 B006 version RT09R20 1.00.00 250318
Description
The device contains an unauthenticated Bluetooth Low Energy access issue. A nearby attacker can connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service, which does not enforce client authentication or command authorization. This allows an attacker within range to bypass the official application and cloud authentication to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qring Smart Ring R20 B006