CVE-2026-79378

Bestechnic Co., Ltd · BES2300 Bluetooth Audio SoC

A vulnerability in the BES2300 Bluetooth Audio SoC firmware allows unauthenticated attackers to cause a Denial of Service via a crafted L2CAP packet.

Executive summary

The Bestechnic BES2300 Bluetooth Audio SoC is vulnerable to a remote Denial of Service attack that can disrupt device connectivity.

Vulnerability

The flaw exists within the btm_acl_handle function, where improper handling of L2CAP packets allows an unauthenticated remote attacker to trigger a system crash or service disruption.

Business impact

The exploitation of this vulnerability results in a Denial of Service, which effectively renders the affected Bluetooth audio device unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk to environments relying on these SoCs, as it can lead to widespread service outages and necessitate manual device resets or recovery procedures.

Remediation

Immediate Action: Contact the hardware manufacturer or firmware provider to obtain the latest firmware update that addresses this btm_acl_handle issue.

Proactive Monitoring: Monitor Bluetooth traffic patterns for spikes in malformed L2CAP packets or sudden, unexplained disconnections across the device fleet.

Compensating Controls: Ensure Bluetooth-enabled devices are physically or logically isolated within secure network segments to limit exposure to untrusted wireless proximity.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant risk to the availability of Bluetooth-based systems using the BES2300 SoC. Organizations should prioritize identifying all affected hardware within their infrastructure and coordinate with their vendors to apply firmware patches as soon as they become available. Failure to address this could leave critical communication or audio systems susceptible to remote disruption.

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources