Fastrack maintains a focused line of embedded security and networking products centered on the Reflex 2.0 platform and its firmware, which occupies a more prominent position in vulnerability tracking than its narrow product scope might suggest. The observed disclosures have been cataloged with placeholder weakness classifications, limiting structural insight into the specific vulnerability patterns affecting this product line; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastrack over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35954HIGH fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the S | Dec 26, 2022 | 8.1 | 26 | NO | NO |
CVE-2021-35953HIGH fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a char | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-35951HIGH fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device. | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-35952MEDIUM fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month via Bluetooth LE Characteristics on handle 0x0017. | Dec 26, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastrack.
Media articles that mention a CVE ID that affects a product developed by Fastrack — matched by CVE ID, not by vendor name.