Description
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over Bluetooth Low Energy (BLE) proximity (Adjacent), requiring no physical contact with the device. Furthermore, the vulnerability is not limited to arbitrary commands but includes cleartext data interception and unauthenticated firmware hijacking via OTA services.
INFO
Published Date :
2026-03-04T00:00:00.000Z
Last Modified :
2026-03-04T16:51:18.362Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-69969 vulnerability.
| Vendors | Products |
|---|---|
| Pebblepower |
|
| Powertech |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-69969.