Description
An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerable locale resides in the l2cap_handle_data() function of the BES2300 Bluetooth Audio SoC firmware, version 3.x and earlier. An attacker who sends a specially crafted L2CAP packet can trigger a denial‑of‑service condition that may bring the hardware to a halt or force a reboot. The flaw results from insufficient validation of incoming L2CAP data, allowing malformed packets to overflow or corrupt execution state, compromise device availability, and disrupt audio services. The direct consequence is loss of service for the device and for any connected clients.

Affected Systems

Affected devices are those that incorporate the Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC with firmware version 3.x and earlier. The product line is the BES2300 Bluetooth Audio SoC. No specific patch version is yet documented, and the vulnerability applies to all firmware builds up to and including v3.x.

Risk and Exploitability

Current exploitation data is limited: the EPSS score is <1%, and the vulnerability is not listed in CISA's KEV catalog. The CVSS score of 8.8 indicates high severity. Nevertheless, the attack vector appears to be Bluetooth traffic, meaning that an adversary with wireless proximity or who has compromised a nearby device could craft the malicious packet. The observed impact is a denial of service, and the risk to availability is moderate to high until the firmware is updated or mitigated. No public exploit code has been reported, but the nature of the flaw suggests straightforward packet crafting could succeed on vulnerable hardware.

Generated by OpenCVE AI on September 10, 2026 at 06:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Bestechnic that includes a patch to l2cap_handle_data() input validation.
  • If updating firmware is not immediately possible, temporarily disable L2CAP support or configure the device to reject all incoming L2CAP packets.
  • Ensure the device is not discoverable or paired unless necessary, to reduce exposure to crafted packets.
  • Deploy network‑level controls such as Bluetooth MAC filtering or physical isolation to limit unauthorized access to the device.
  • Monitor logs or device telemetry for abnormal reset or crash events that may indicate attempted DoS activity.

Generated by OpenCVE AI on September 10, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Denial of Service in BES2300 Bluetooth Audio SoC via crafted L2CAP packet
Weaknesses CWE-119

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1284
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Bestechnic
Bestechnic bes2300
Vendors & Products Bestechnic
Bestechnic bes2300

Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Denial of Service in BES2300 Bluetooth Audio SoC via crafted L2CAP packet
Weaknesses CWE-119
CWE-20

Tue, 08 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
References

Subscriptions

Bestechnic Bes2300
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T18:15:37.872Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79376

cve-icon Vulnrichment

Updated: 2026-09-08T18:14:52.165Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T14:17:28.320

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-79376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:45:12Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-20

    Improper Input Validation