CISA warns of Bluetooth flaws in Fourth Frontier cardiac monitors

Critical vulnerabilities allow attackers to manipulate device functions and inject fake health data without authentication.

Illustration: CISA warns of Bluetooth flaws in Fourth Frontier cardiac monitors

Critical vulnerabilities allow attackers to manipulate device functions and inject fake health data without authentication.

  • Fourth Frontier’s Frontier X cardiac monitoring devices contain critical Bluetooth vulnerabilities allowing unauthenticated access
  • Attackers can manipulate device functions, inject fake health telemetry, and potentially cause patient harm
  • Affected versions include Android app

The Cybersecurity and Infrastructure Security Agency has issued a medical device advisory warning of critical vulnerabilities in Fourth Frontier’s cardiac monitoring systems that could allow attackers to manipulate patient health data and device functions.

The vulnerabilities affect the Frontier X and Frontier X2 cardiac monitoring devices and their mobile applications, which are deployed worldwide across healthcare systems.

The primary vulnerability, tracked as CVE-2026-5768 with a CVSS score of 8.8, stems from missing authentication controls in the devices’ Bluetooth Low Energy implementation. The Frontier X2 device allows unauthenticated read and write access to critical GATT characteristics without requiring device pairing or authorisation.

According to CISA’s advisory, attackers within Bluetooth range can perform unauthorised control of device functions, including starting and stopping activities, triggering vibrations, and causing denial-of-service conditions. The vulnerability also allows attackers to fuzz characteristic values to induce unexpected device behaviour.

The security flaws extend to the mobile applications, which lack proper Bluetooth device authentication. This allows attackers to impersonate legitimate Frontier X2 devices by cloning Bluetooth advertisements and exposing expected GATT characteristics.

Through this impersonation, attackers can manipulate activity states and inject fabricated health telemetry into the mobile application, including false readings for breathing rate, heart rate, strain, and other health-related metrics.

The affected versions include the Frontier X Android application versions prior to v15.0.0, iOS application versions prior to v25.0.0, and all versions of the Frontier X2 device hardware.

CISA warns that successful exploitation could allow attackers to read and write arbitrary handle values and change clinical readings, potentially resulting in device takeover and patient harm.

Why It Matters

This advisory highlights critical gaps in medical device security that directly impact patient safety and data integrity. For CISOs in healthcare organisations, these vulnerabilities represent both immediate operational risks and potential regulatory compliance issues under medical device security frameworks.

The ability for attackers to inject false health telemetry could compromise clinical decision-making and patient care protocols. Healthcare CISOs must assess their medical device inventories for similar Bluetooth authentication weaknesses and evaluate network segmentation strategies to limit attack vectors against connected medical devices.

What To Do Now

  • Review medical device inventories for Fourth Frontier cardiac monitoring systems and identify affected versions per CISA’s advisory
  • Implement network segmentation to isolate medical devices from general network infrastructure where possible
  • Coordinate with clinical teams to assess patient safety protocols when using affected devices until patches are available

Sources