CVE-2026-49994 Bluehood 认证绕过漏洞
影响未授权攻击者可读取蓝牙追踪数据并篡改应用配置
Bluehood 是一款监控本地蓝牙活动的应用。在 0.7.1 版本之前,当启用 auth_enabled 时,仅 HTML 页面处理器执行会话校验,而 /api/* 接口完全未做认证检查。攻击者无需会话 Cookie 即可访问这些接口。
影响范围
Bluehood 0.7.1 之前的版本,具体受影响版本范围暂无更详细的公开信息。
漏洞详情
该漏洞属于缺失认证/访问控制不当。当启用认证后,/api/* 下的 settings、devices、groups 以及 /api/device/{mac}/notes 等接口未调用任何认证检查,导致网络攻击者可直接调用这些接口。利用方式为直接向仪表盘端口发送 API 请求,读取蓝牙追踪数据并修改心跳 URL、保留策略、设备分组及设备备注等状态。
利用条件与风险
利用前提是攻击者能访问仪表盘端口且目标启用了 auth_enabled。由于无需任何凭据即可读写敏感数据与配置,实战风险高。
修复建议
官方已在 0.7.1 版本中修复,建议升级至 0.7.1 或更高版本。临时缓解措施包括限制仪表盘端口的网络访问,暂无其他公开信息。
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.