VendorsFastrackreflex_2.0any version
Vulnerabilities

Fastrack Reflex 2.0 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-35954
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature.
Published 2022-12-26 · Modified
8.1EPSS 0.003
CVE-2021-35951
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device.
Published 2022-12-26 · Modified
7.5EPSS 0.009
CVE-2021-35953
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a characteristic value.
Published 2022-12-26 · Modified
7.5EPSS 0.008
CVE-2021-35952
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month via Bluetooth LE Characteristics on handle 0x0017.
Published 2022-12-26 · Modified
5.3EPSS 0.006