CVE-2025-69969Disclosure(pebblepower / pebble_prism_ultra)

LOWCVSS 9.6 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over Bluetooth Low Energy (BLE) proximity (Adjacent), requiring no physical contact with the device. Furthermore, the vulnerability is not limited to arbitrary commands but includes cleartext data interception and unauthenticated firmware hijacking via OTA services.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-311CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pebble_prism_ultra
  • pebble_prism_ultra_firmware

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
pebble_prism_ultrapebble_prism_ultra_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-04: 4Technical Details · 2026-03-04: 403-04
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-69969 A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allo… https://www.cve.org/CVERecord?id=CVE-2025-69969 ----- Traducción: CVE-2025-69969 Fal… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑69969 as a lack of authentication and authorization in SRK Powertech Pebble Prism Ultra v2.9.2’s BLE protocol, with no PoC, exploit tool, or patch details provided.

    00010119
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-69969 A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allo… https://www.cve.org/CVERecord?id=CVE-2025-69969

    Post summary

    The text identifies CVE‑2025‑69969 with a brief technical description but provides no evidence of PoC, exploit, active use, or mitigation, resulting in a low‑confidence general classification.

    00010480
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-69969: CRITICAL] Vulnerability in SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers via BLE proximity to execute arbitrary commands, intercept cleartext data, and hijack unauthentica...#cve,CVE-2025-69969,#cybersecurity https://cvefind.com/CVE-2025-69969

    Post summary

    The tweet announces a critical BLE proximity vulnerability in SRK Powertech’s Pebble Prism Ultra v2.9.2 that allows arbitrary command execution and data interception, with no PoC, exploit, or active exploitation claims provided.

    00010107
    595 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-69969 - Critical A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to rever... https://www.thehackerwire.com/vulnerability/CVE-2025-69969/ https://t.co/hzGLryYjZa

    Post summary

    A critical authentication flaw in SRK Powertech Pebble Prism Ultra’s BLE protocol is disclosed, with technical details but no PoC, exploit, patch, or active exploitation evidence.

    00010136
    121 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWpebblepowerpebble_prism_ultra---
OSpebblepowerpebble_prism_ultra_firmware---

Explore more