Medium severity6.1NVD Advisory· Published Apr 4, 2018· Updated Jun 17, 2026
CVE-2018-9119
CVE-2018-9119
Description
An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentication is needed, as demonstrated by gatttool.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: MCU firmware 0.1.73, BLE firmware 0.7.4
- cpe:2.3:o:brilliantts:fuze_card_ble_firmware:0.7.4:*:*:*:*:*:*:*
- cpe:2.3:o:brilliantts:fuze_card_mcu_firmware:0.1.73:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- blog.ice9.us/2018/04/stealing-credit-cards-from-fuze-bluetooth.htmlnvdThird Party Advisory
- ice9.us/advisories/ICE9-2018-001.txtnvdThird Party Advisory
- www.reddit.com/r/netsec/comments/89qrp1/stealing_credit_cards_from_fuze_via_bluetooth/nvdIssue Tracking
- www.elttam.com/blog/fuzereview/nvd
News mentions
0No linked articles in our index yet.