Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-39081 PoC — TREEL Mobility SMART TYRE CAR & BIKE 安全漏洞

Source
Associated Vulnerability
Title:TREEL Mobility SMART TYRE CAR & BIKE 安全漏洞 (CVE-2024-39081)
Description:TREEL Mobility SMART TYRE CAR & BIKE是TREEL Mobility公司的一个智能的轮胎保护和管理解决方案。 TREEL Mobility SMART TYRE CAR & BIKE v4.2.0版本存在安全漏洞,该漏洞源于 允许攻击者通过蓝牙通信执行中间人攻击。
Description
CVE-2024-39081. BLE TPMS data manipulation over bluetooth communication.
Readme
# CVE-2024-39081
  Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39081
  
# BLE BASED TREEL TPMS for bikes
Here, we performed and explained TPMS data manipulation over bluetooth. we can send false alarm to App user over bluetooth. Detailed vulnerability findings and analysis are stored in the repository.
File Name - Treel_BLE_TPMS_Penetration_Testing_Report.pdf
# About Product

TREEL TPMS, powered by JK Tyre, is a new-age tyre performance and maintenance system based on cutting-edge technology. This evolved safety system protects riders, drivers and passengers from unforeseen risks. By continuously monitoring vehicle tyres and vehicle performance, while flagging up anomalies. It also improves vehicle mileage significantly, and extends the life of your tyres and vehicle. It’s your personal safety guardian, predicting and preventing accidents, and protecting you, your family, and your vehicle.

link: https://treel.in/buy-products/

![App Screenshot](https://m.media-amazon.com/images/I/51MB7OoJw4L._SL1500_.jpg)

# Application 

 app link : https://play.google.com/store/apps/details?id=com.treel.android&hl=en&gl=US

![App Screenshot](https://play-lh.googleusercontent.com/AmP1QTecJg8dT6Ro2prsNNWXhbSj2GEy-L6FC_uy61fKGC1kOmLTuuf-FD33ivIKtVk=w480-h960-rw)







File Snapshot

[4.0K] /data/pocs/875807b7310e583dcb157acbe8ae6faebe3e6122 ├── [1.3K] README.md └── [511K] Treel_BLE_TPMS_Penetration_Testing_Report.pdf 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.