Back to all lessons
Awareness Lessons
4 months ago

Unencrypted BLE Transmission and DoS Flaw Expose Apollo Pharmacy Glucose Monitor Users

The Apollo Pharmacy APG-01 BT blood glucose monitor contains two serious vulnerabilities: one allowing passive interception of sensitive health data over Bluetooth Low Energy (CVE-2026-50034), and another enabling denial-of-service by monopolizing the device's single connection slot (CVE-2026-52866). These flaws are particularly dangerous because they target a medical device that handles protected health information (PHI), meaning real patients could have their glucose readings exposed or be locked out of a life-relevant monitoring tool. The situation is compounded by Apollo Pharmacy's failure to respond to CISA's coordination requests, leaving users with no vendor-issued remediation path. This highlights the broader risk of IoT and connected medical devices entering the market without adequate security validation or post-market vulnerability response processes.

Tactical Insight

Immediate actions

  • Disable Bluetooth on the APG-01 BT device when not actively in use to minimize the attack surface for nearby adversaries.
  • Avoid using the device in public or high-density areas where malicious actors within BLE range could intercept transmissions.
  • Contact Apollo Pharmacy directly and request a security patch or firmware update timeline, escalating to regulatory bodies (e.g., FDA, CISA) if unresponsive.

Long-term improvements

  • Require BLE-enabled medical devices to implement authenticated and encrypted communication (e.g., BLE pairing with AES-128) before procurement or deployment.
  • Establish a vendor security assessment process that includes mandatory incident response SLAs as a condition of supplier contracts.
  • Maintain an inventory of all connected medical devices and track their CVE exposure using a vulnerability management platform.

Detection & monitoring measures

  • Deploy BLE monitoring tools in clinical environments to detect unauthorized scanning or connection attempts targeting medical devices.
  • Subscribe to CISA ICS-CERT advisories and automate alerting for CVEs affecting devices in your organization's medical device inventory.
  • Implement network/RF anomaly detection to identify unusual Bluetooth activity patterns indicative of connection-slot exhaustion (DoS) attacks.