Skip to main content

Smart Scale - Security Analysis

Device Profile

PropertyValue
Device NameYoda1 / QN-Scale
Companion App"Yolanda Health"
Manufacturer ID0x05C0

Executive Summary

The smart scale sends weight data unencrypted in BLE advertising packets. Anyone with a BLE scanner in range (~10m) can read the weight in real-time.

Finding

FindingCVSSSeverity
F-001: Weight in Advertising5.3Medium

Privacy Impact

An attacker can:

  • ✗ Read weight in real-time
  • ✗ Track weight over time
  • ✗ Identify person via MAC
  • ✗ Purely passive, no connection needed!