A critical security vulnerability has been discovered in the Amp'ed RF BT-AP 111 Bluetooth Access Point, exposing organizations to significant security risks through an unauthenticated management interface.
See also: GitLab patches vulnerabilities for DoS & SSRF attacks

The device, which acts as a Bluetooth- to -Ethernet supporting both access point and gateway functionality, lacks fundamental authentication controls in the web-based management system.
The vulnerability, designated as CVE-2025-9994, allows remote attackers with network access to gain complete administrative control of the device without requiring credentials. This flaw affects the HTTP-based administrative interface, which manages critical functions including Bluetooth settings, network parameters, and security settings.
The BT-AP 111 supports Universal Plug and Play (UPnP) on the Ethernet side and can handle up to seven simultaneous Bluetooth connections via the UART Serial.
See also: Microsoft warns of vulnerability in Active Directory Domain Services

Analysts from Carnegie Mellon University discovered this vulnerability through research by the CERT Coordination Center, noting the device's failure to implement basic security checks. The researchers noted that this configuration violates established NIST security guidelines, specifically SP 800-121 Rev. 2, which requires authentication for Bluetooth devices at Service Level 2 or higher.
The vulnerability arises from the complete absence of authentication mechanisms in the device's web interface architecture. Unlike typical network devices that implement login screens or certificate-based authentication, the BT-AP 111 directly exposes its admin panel to any user who has access to its HTTP port.
This design flaw allows attackers to modify device configurations, change Bluetooth , and potentially intercept or manipulate data flowing through the bridge. The exploit only requires network connectivity to the targeted device, making it accessible to both local network attackers and, in poorly configured environments, remote threats.
See also: Chrome update fixes critical RCE vulnerability

Given the manufacturer's lack of response to notification efforts, security professionals recommend isolating affected devices in segregated network segments that are inaccessible to untrusted users until appropriate authentication controls can be implemented.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
