Impact
A heap overflow exists in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware. The overflow is triggered by a crafted L2CAP packet, leading to a denial of service by disrupting audio functionality. The vendor’s description does not mention any impact on confidentiality or integrity, so it is inferred that these aspects are not affected.
Affected Systems
The flaw affects BES2300 firmware versions 3.x and earlier. Devices using any of these firmware releases from Bestechnic Co., Ltd are vulnerable. No CNA product is listed, so vulnerable devices may be identified by the SoC model or firmware release name.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, while the lack of EPSS data and absence from CISA KEV suggests the exploit is not yet widely used. The attacker must transmit a malicious L2CAP packet via Bluetooth, likely requiring proximity. No publicly available exploits have been documented, but a heap overflow could be relatively simple to trigger once the device’s Bluetooth interface is reachable.
OpenCVE Enrichment