CVE-2025-69969

CRITICAL

SRK Powertech Pebble Prism Ultra 2.9.2 - Command Injection

Title source: llm
STIX 2.1

Description

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over Bluetooth Low Energy (BLE) proximity (Adjacent), requiring no physical contact with the device. Furthermore, the vulnerability is not limited to arbitrary commands but includes cleartext data interception and unauthenticated firmware hijacking via OTA services.

Scores

CVSS v3 9.6
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-311 CWE-319
Status published
Products (1)
pebblepower/pebble_prism_ultra_firmware < 2.5.8
Published Mar 04, 2026
Tracked Since Mar 05, 2026