logo

BLUUID: Firewallas, Diabetics, And… Bluetooth

ID: 37c9de9e-35a7-525c-a765-76e189c89f45

STIX ID: report--37c9de9e-35a7-525c-a765-76e189c89f45

Feed Name: GreyNoise Labs

Threat Score
78/100

Date Published: 2024-08-20

Date Updated: 2026-04-27

Author: Remy

...
...

This report describes a methodology for creating a BTLE GATT UUID database from Android APKs to remotely fingerprint devices and demonstrates its use by identifying Firewalla devices, where researchers discovered and demonstrated two serious vulnerabilities: CVE-2024-40892 (exposure and weak protection of the device license/token and reused private signing key enabling forged JWTs and unauthorized configuration/SSH provisioning) and CVE-2024-40893 (unsanitized network configuration parameters exposed via BTLE allowing command injection and remote root code execution with persistence via cloud sync).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.