CVE-2026-52866 PUBLISHED

Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization

Assigner: icscert
Reserved: 10.06.2026 Published: 18.06.2026 Updated: 18.06.2026

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Apollo Pharmacy
Product Blood Glucose Monitoring System (Model No. APG-01 BT)
Versions Default: unaffected
  • Version 0x0110_v1.1.0 is affected

Workarounds

Apollo Pharmacy did not respond to CISA's requests to coordinate. Users are encouraged to reach out to Apollo Pharmacy directly for more information: https://www.apollopharmacy.in/contact-us

CISA recommends users follow the guidance in the Understanding Bluetooth Technology blog:  https://www.cisa.gov/news-events/news/understanding-bluetooth-technology

Credits

  • Rishitha Pucchakayala and Centre for Development of Advanced Computing (Hyderabad) reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-862 CWE