CVE-2026-79378
Bestechnic Co., Ltd · BES2300 Bluetooth Audio SoC
A vulnerability in the BES2300 Bluetooth Audio SoC firmware allows unauthenticated attackers to cause a Denial of Service via a crafted L2CAP packet.
Executive summary
The Bestechnic BES2300 Bluetooth Audio SoC is vulnerable to a remote Denial of Service attack that can disrupt device connectivity.
Vulnerability
The flaw exists within the btm_acl_handle function, where improper handling of L2CAP packets allows an unauthenticated remote attacker to trigger a system crash or service disruption.
Business impact
The exploitation of this vulnerability results in a Denial of Service, which effectively renders the affected Bluetooth audio device unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk to environments relying on these SoCs, as it can lead to widespread service outages and necessitate manual device resets or recovery procedures.
Remediation
Immediate Action: Contact the hardware manufacturer or firmware provider to obtain the latest firmware update that addresses this btm_acl_handle issue.
Proactive Monitoring: Monitor Bluetooth traffic patterns for spikes in malformed L2CAP packets or sudden, unexplained disconnections across the device fleet.
Compensating Controls: Ensure Bluetooth-enabled devices are physically or logically isolated within secure network segments to limit exposure to untrusted wireless proximity.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to the availability of Bluetooth-based systems using the BES2300 SoC. Organizations should prioritize identifying all affected hardware within their infrastructure and coordinate with their vendors to apply firmware patches as soon as they become available. Failure to address this could leave critical communication or audio systems susceptible to remote disruption.
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written