← Registry

CPATH-2026-0001 · WEARABLE HEALTH

Qardio Arm — static credentials → engineering backdoor

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence ACCOUNT_AUTHORITY authority · Evidence EV:3 (reproduced / report-backed) · Liveness HISTORICAL
CPATH IDCPATH-2026-0001
CVE(s)CVE-2025-20615
Device / classQardio Arm blood-pressure monitor + iOS app (WEARABLE HEALTH)
VendorQardio
Dominant consequenceACCOUNT_AUTHORITY (authority)
Paths verdictCRITICAL (worst of 1 path)
Published baseline
v3.1 6.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
v3.1 6.2 MEDIUM CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L · CISA ICSMA-25-044-01
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

authority

ACCOUNT_AUTHORITY

CRITICAL
Reachability RE:3
Complexity EC:4
Consequence ACCOUNT_AUTHORITY
Scale SR:4 / SX:4
Verdict CRITICAL
Reachability 3
Complexity 4
Exposure 3
Physical / safety 0
Data / perception 3
Authority 3
Chainability 3
Reuse scale 4
Execution scale 4
Recovery 3
Evidence EV:3 · reproduced / report-backed
Liveness HISTORICAL
Vector CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:0/DP:3/AT:3/CH:3/SR:4/SX:4/OR:3/EV:3/LS:HISTORICAL

TL;DR

The Paths model rates this CRITICAL because a single static credential shipped in every downloadable app copy yields production engineering authority across the deployed fleet. The published 6.2/6.6 Medium baseline is retained for source review; the Paths driver is fleet-scale authority transfer from a reusable app artifact.

What it is

The Qardio Arm iOS app ships static, production-level credentials in a .plist file. Extracting them unlocks an engineering/dev account on api.getqardio.com plus an engineering backdoor that issues raw hex commands to the cardiac-adjacent device over BLE. (CISA ICSMA-25-044-01.)

Published baseline — scope note

AV:P (Physical) is the suppressor. FIRST scores Attack Vector relative to the vulnerable component. The analyst modeled the component as “a victim’s installed phone,” requiring physical extraction. But the secret is identical in every downloadable copy — the real component is the distributed app artifact, read from the attacker’s own device. That is AV:N, and reading a file from your own app copy needs no privilege (PR:N). The CWE-359 (“private info exposure”) label also understates a privileged backdoor as a privacy leak.

Consequence driver

The Paths model highlights dimension #1 (blast-radius/scale-of-reuse): one extracted credential yields standing engineering-backdoor authority across the deployed fleet. The published baseline depends on a component model that treats the vulnerable artifact as a victim phone (AV:P). The leak is remote and reusable; kinetic BLE delivery remains local.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0001 (“Qardio Arm — static credentials → engineering backdoor”), paths.cfse.ai/CPATH-2026-0001 (published 2026-06-03).