Description
An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The btm_acl_handle() function in Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier contains a flaw that allows an attacker to cause a denial of service by sending a crafted L2CAP packet. This malformed packet can trigger the Bluetooth stack to become unresponsive, leading to a loss of connectivity or requiring a hardware reset. The vulnerability does not require user authentication or privileged access; it merely relies on the ability to send the malformed packet to the SoC.

Affected Systems

Devices powered by the BES2300 Bluetooth Audio SoC running firmware version 3.x or earlier are affected. This includes any embedded systems or peripherals that incorporate this SoC and run the vulnerable firmware.

Risk and Exploitability

The exploit does not require elevated privileges and can be performed from a device that can transmit L2CAP traffic. Based on the description, the attack vector likely requires short‑range proximity to the SoC, but this is inferred rather than explicitly documented. The CVSS score of 7.5 indicates a high‑severity denial of service vulnerability. The EPSS score of < 1 % implies a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. Nevertheless, the ability to permanently incapacitate the device makes this a high‑consequence denial of service risk for deployed systems.

Generated by OpenCVE AI on September 10, 2026 at 05:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest BES2300 firmware release (v4.x or later) from Bestechnic when available.
  • If no firmware update is available, disable Bluetooth functionality on the device when it is not in active use to prevent acceptance of malformed packets.
  • Implement logging and monitoring of L2CAP traffic to detect anomalous packets and trigger an automatic reset or reboot of the Bluetooth subsystem.
  • Consider applying a firewall or traffic filtering mechanism at the host level to drop suspicious L2CAP frames before they reach the SoC.

Generated by OpenCVE AI on September 10, 2026 at 05:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Bluetooth L2CAP Packet–Based Denial of Service in Bestechnic BES2300 Firmware

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted L2CAP Packet in Bestechnic BES2300 Bluetooth Audio SoC Firmware
Weaknesses CWE-20

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted L2CAP Packet in Bestechnic BES2300 Bluetooth Audio SoC Firmware
Weaknesses CWE-20

Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Bestechnic
Bestechnic bes2300
Vendors & Products Bestechnic
Bestechnic bes2300

Tue, 08 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
References

Subscriptions

Bestechnic Bes2300
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T14:55:52.090Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79378

cve-icon Vulnrichment

Updated: 2026-09-09T14:55:47.165Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T14:17:28.573

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-79378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:00:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption