CVE-2026-50034 PUBLISHED

Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensitive Information

Assigner: icscert
Reserved: 10.06.2026 Published: 18.06.2026 Updated: 18.06.2026

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Apollo Pharmacy
Product Blood Glucose Monitoring System (Model No. APG-01 BT)
Versions Default: unaffected
  • Version 0x0110_v1.1.0 is affected

Workarounds

Apollo Pharmacy did not respond to CISA's requests to coordinate. Users are encouraged to reach out to Apollo Pharmacy directly for more information: https://www.apollopharmacy.in/contact-us

CISA recommends users follow the guidance in the Understanding Bluetooth Technology blog:  https://www.cisa.gov/news-events/news/understanding-bluetooth-technology

Credits

  • Rishitha Pucchakayala and Centre for Development of Advanced Computing (Hyderabad) reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-319 CWE