CVE-2026-89034: TCH QRing R20_B006 Unauthenticated BLE Access

Published Sep 16, 2026
·
Updated

TCH QRing smart ring model R20B006 running firmware RT09R201.00.00250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.

Affected Software

1 affected component
TCH QRing Smart ring model R20_B006=RT09R20_1.00.00_250318

Event History

Sep 16, 2026
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any attacker within Bluetooth Low Energy range of an affected ring can exploit it. No pairing, prior access, authentication, or user approval is required.

2

What access does the exposed service provide?

An attacker can read battery levels, start live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records. The attacker can do this directly over Bluetooth Low Energy without using the official application or cloud authentication.

3

Is user interaction required for exploitation?

No. The issue is reachable over Bluetooth Low Energy and does not require privileges or user interaction.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203