CVE-2026-79376
massUnauthenticated L2CAP DoS in Bestechnic BES2300 Bluetooth Audio SoC Firmware
CVE-2026-79376 is an improper input validation flaw (CWE-20, CWE-1284) in the l2cap_handle_data() function of Bestechnic's BES2300 Bluetooth audio SoC firmware, version 3.x and earlier. An attacker within Bluetooth range can trigger it by sending a crafted L2CAP packet to an affected device, with no authentication or user interaction required. The described impact is denial of service (the audio device crashes or hangs), although the published CVSS 3.1 vector (8.8, AV:A/AC:L/PR:N/UI:N) rates confidentiality, integrity, and availability impacts all as High. Any product built on a BES2300 chip — typically true wireless earbuds, headsets, and speakers — running firmware v3.x or earlier is affected. There is no known public proof of concept, the issue is not in CISA's KEV, and EPSS assigns a 0.2% probability of exploitation within 30 days, so no exploitation is known.
What to do: Owners of BES2300-based audio devices should check with the product vendor for firmware updates built on a BES2300 SDK newer than v3.x and apply them when available; because the flaw is in chip firmware, fixes must arrive through OEM product firmware rather than OS patches. Until patching is possible, reduce exposure in sensitive environments by disabling Bluetooth or discoverability on affected devices and limiting connections from unpaired nearby attackers.
| Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware | v3.x and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
- Weakness
- CWE-20, CWE-1284
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.