Impact
The btm_acl_handle() function in Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier contains a flaw that allows an attacker to cause a denial of service by sending a crafted L2CAP packet. This malformed packet can trigger the Bluetooth stack to become unresponsive, leading to a loss of connectivity or requiring a hardware reset. The vulnerability does not require user authentication or privileged access; it merely relies on the ability to send the malformed packet to the SoC.
Affected Systems
Devices powered by the BES2300 Bluetooth Audio SoC running firmware version 3.x or earlier are affected. This includes any embedded systems or peripherals that incorporate this SoC and run the vulnerable firmware.
Risk and Exploitability
The exploit does not require elevated privileges and can be performed from a device that can transmit L2CAP traffic. Based on the description, the attack vector likely requires short‑range proximity to the SoC, but this is inferred rather than explicitly documented. The CVSS score of 7.5 indicates a high‑severity denial of service vulnerability. The EPSS score of < 1 % implies a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. Nevertheless, the ability to permanently incapacitate the device makes this a high‑consequence denial of service risk for deployed systems.
OpenCVE Enrichment