Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sweyntooth_bluetooth_low_energy_attacks — Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities. | Kitploit
Tools/GitHubGitHub/matheus-garbelini/sweyntooth_bluetooth_low_energy_attacks
Bluetooth SecurityPayload GenerationVulnerability AnalysisExploitationFuzzingWireless SecurityPenetration TestingHardware & IoT Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
matheus-garbelini/sweyntooth_bluetooth_low_energy_attacks

sweyntooth_bluetooth_low_energy_attacks

Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities.

View Repository
33277324 years agoReviewed by Kitploit

SweynTooth - Unleashing Mayhem over Bluetooth Low Energy

This repository is part of a research outcome from the ASSET Research Group. attack_logo

SweynTooth captures a family of 18 vulnerabilities across different Bluetooth Low Energy (BLE) software development kits (SDKs) of six major system-on-a-chip (SoC) vendors. The vulnerabilities expose flaws in specific BLE SoC implementations that allow an attacker in radio range to trigger deadlocks, crashes and buffer overflows or completely bypass security depending on the circumstances. (Update) We have also included a testing script to check devices against the BLE KNOB variant.

You can check more information about the vulnerabilities, available patches and affected devices on ASSET Research Group SweynTooth disclosure website.

Fitbit, August Smart Lock, Eve Energy, CubiTag and other "Smart" things are affected.

  • Fitbit Inspire Crash & CubiTag deadlock - https://www.youtube.com/watch?v=Iw8sIBLWE_w
  • Eve Energy & August Smart Lock crash - https://www.youtube.com/watch?v=rge1XeJVpag&t=6s

Libraries included in this PoC

This PoC uses well maintained libraries such as Scapy and Colorama. The BLE packet crafting and dissection is done via customized Scapy protocol layers (bluetooth4LE and bluetooth.py). There's a merge in progress to include our additions in Scapy's main repository.

Getting Started (Installation)

First, you must make sure to have a Python2.7 on your system and the python packages listed on requirements.txt file. If you are using Ubuntu, run the following:

sudo apt-get install python2.7
sudo pip install -r requirements.txt

Secondly, SweynTooth uses the Nordic nRF52840 Dongle to send/receive raw link layer packets to and from the vulnerable peripheral over the air. It is necessary to flash the driver firmware to the board before starting the Python 2.7 scripts.

The binary of our firmware code is on the nRF52_driver_firmware.zip file. You need to install nrfutil tool to flash the firmware on the board. Remember to put the nRF52840 on DFU mode before flashing (reset the USB dongle while it is connected to your PC by pressing the small reset button).

dongle_reset_button

You can run the following commands to install the Python dependencies and to flash the firmware:

python -m pip install nrfutil pyserial pycryptodome
nrfutil dfu usb-serial -p COM_PORT -pkg nRF52_driver_firmware.zip

The scripts work on Linux or Windows. You just need to change the COM_PORT parameter to match the nRF52840 port name.

(Alternative nRF52 driver flashing method)

If the previous flashing method didn't work, you can also flash the firmware by using the nRF Connect App for Desktop, which gives a nice interface to flash the hex firmware (nRF52_driver_firmware.hex).

Running the proof of concept scripts

After the requirements are installed, you can run an exploit script by executing the following command:

python Telink_key_size_overflow.py COM7 A4:C1:38:D8:AD:A9

The first argument is the serial port name (generally /dev/ttyACM0 on Linux) and the second is the address of the vulnerable BLE device. You can use any BLE scanner or the nRF Connect App to discover such address.

Taking as example the Key Size Overflow vulnerability, the following output is given by the script if the vulnerable device hangs after the crash:

attack_logo

Docker image for Linux (optional)

If you wish to use SweynTooth via a docker image to avoid install Python dependencies, you can use the docker.sh helper script to build and run the docker instance or download the prebuild docker image (link) available on releases page. The usage of docker.sh is described below.

---------  HELP -------------
sudo ./docker run <script_name> <serial_port> <ble_target_address> - Start any sweyntooth script by its name (<script_name>)
sudo ./docker build                                                - Build docker container
sudo ./docker build release                                        - Build docker container and create compressed image for release
sudo ./docker shell                                                - Start docker container shell
---------- EXAMPLE ----------
./docker.sh run extras/Microchip_and_others_non_compliant_connection.py /dev/ttyACM0 f0:f8:f2:da:09:63

Available BLE exploits

Each exploit script corresponds to one flaw. The following summary table captures the correspondence between the vulnerability and a script to exploit the vulnerability on the affected SoCs.

VulnerabilityCVE(s)VendorScript file
Link Layer Length OverflowCVE-2019-16336
CVE-2019-17519
Cypress
NXP
link_layer_length_overflow.py
LLID DeadlockCVE-2019-17061
CVE-2019-17060
Cypress
NXP
llid_dealock.py
Truncated L2CAPCVE-2019-17517DialogDA14580_exploit_att_crash.py
Silent Length OverflowCVE-2019-17518DialogDA14680_exploit_silent_overflow.py
Download Tool