CVE-2021-40526 is an incorrect buffer size calculation vulnerability affecting Peloton TTR01 devices, including firmware up to PTV55G. A remote attacker can exploit a heap overflow in the GymKit daemon's network server, leading to a Denial of Service (DoS) attack that prevents Apple MFI devices from authenticating with the Peloton Bike. Rated Medium severity (CVSS 5.3), this vulnerability requires no user interaction and has low attack complexity, but only impacts availability. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= ptv55gCPE matchmatch criteria | cpe:2.3:o:onepeloton:ttr01_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.