Digging into the paper, the significant finding (RCE) is achieved via:
A payload was written which installs a reverse shell backdoor for root persistence. The payload was sent from a computer hosting a Wi-Fi to which the watch was connected, to ensure the watch had a reachable IPv4 address. The program ncat was used both to send the payload to the watch's network service, and to catch reverse shell connections.
So if i understand this- it requires the watch being connected to a compromised AP. Anyone get a different read?