CVE-2025-69821

7.4

Beat XP · VEGA Smartwatch

A denial of service vulnerability in the Beat XP VEGA Smartwatch firmware allows unauthenticated attackers to disrupt device functionality via the Bluetooth Low Energy (BLE) connection.

Executive summary

A vulnerability in the Beat XP VEGA Smartwatch firmware allows an unauthenticated attacker to cause a denial of service via the device BLE interface.

Vulnerability

This vulnerability involves a denial of service flaw triggered through the Bluetooth Low Energy (BLE) connection, requiring no authentication by the attacker.

Business impact

The ability for an attacker to remotely trigger a denial of service on a wearable device can lead to a complete loss of device availability and functionality. Given the CVSS score of 7.4, this vulnerability represents a significant risk to device reliability and user safety, potentially disrupting critical health monitoring or connectivity features.

Remediation

Immediate Action: Since no patch is currently confirmed, users should restrict BLE connectivity to known, trusted environments and disable Bluetooth on the device when not in use.

Proactive Monitoring: Monitor the device for unexpected reboots, unresponsive interfaces, or sudden loss of connectivity, which may indicate an exploitation attempt.

Compensating Controls: Limit exposure by keeping the smartwatch away from untrusted Bluetooth devices and avoiding pairing in public or high risk areas.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository referenced by the CVE record.

Analyst recommendation

The vulnerability poses a credible risk to the operational integrity of the Beat XP VEGA Smartwatch. Because an exploit is publicly available, users must remain vigilant and apply any future vendor security updates immediately upon release to restore device security.

Sources