Description

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over Bluetooth Low Energy (BLE) proximity (Adjacent), requiring no physical contact with the device. Furthermore, the vulnerability is not limited to arbitrary commands but includes cleartext data interception and unauthenticated firmware hijacking via OTA services.

INFO

Published Date :

2026-03-04T00:00:00.000Z

Last Modified :

2026-03-04T16:51:18.362Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-69969 vulnerability.

Vendors Products
Pebblepower
  • Pebble Prism Ultra
  • Pebble Prism Ultra Firmware
Powertech
  • Pebble Prism Ultra
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-69969.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact