Impact
The vulnerable locale resides in the l2cap_handle_data() function of the BES2300 Bluetooth Audio SoC firmware, version 3.x and earlier. An attacker who sends a specially crafted L2CAP packet can trigger a denial‑of‑service condition that may bring the hardware to a halt or force a reboot. The flaw results from insufficient validation of incoming L2CAP data, allowing malformed packets to overflow or corrupt execution state, compromise device availability, and disrupt audio services. The direct consequence is loss of service for the device and for any connected clients.
Affected Systems
Affected devices are those that incorporate the Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC with firmware version 3.x and earlier. The product line is the BES2300 Bluetooth Audio SoC. No specific patch version is yet documented, and the vulnerability applies to all firmware builds up to and including v3.x.
Risk and Exploitability
Current exploitation data is limited: the EPSS score is <1%, and the vulnerability is not listed in CISA's KEV catalog. The CVSS score of 8.8 indicates high severity. Nevertheless, the attack vector appears to be Bluetooth traffic, meaning that an adversary with wireless proximity or who has compromised a nearby device could craft the malicious packet. The observed impact is a denial of service, and the risk to availability is moderate to high until the firmware is updated or mitigated. No public exploit code has been reported, but the nature of the flaw suggests straightforward packet crafting could succeed on vulnerable hardware.
OpenCVE Enrichment