CVE-2026-79378
massUnauthenticated L2CAP DoS in Bestechnic BES2300 Bluetooth Audio SoC firmware
CVE-2026-79378 is a denial-of-service flaw in the btm_acl_handle() function of the firmware running on Bestechnic's BES2300 Bluetooth audio SoC, versions v3.x and earlier. An attacker within Bluetooth range can trigger it by sending a specially crafted L2CAP packet to an affected device; the malformed input crashes the firmware's ACL-link handling, causing the audio device to stop responding until it is reset or rebooted. Because the attack requires no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), any nearby unpaired or paired device that can reach the Bluetooth stack is a potential source of the malicious packet. The flaw affects any consumer audio product — wireless earbuds, headphones, speakers, soundbars — built on the BES2300 and shipped with firmware v3.x or earlier, though the exact affected end products and fixed firmware version are not specified in the available data. As of now there is no known public proof-of-concept, the CVE is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at a low 0.2%, so no active exploitation is known.
What to do: Identify which of your Bluetooth audio products (earbuds, headsets, speakers) are built on a Bestechnic BES2300 SoC and check with the device vendor for firmware updates beyond the v3.x line, as the fixed version is not stated in the available data. As an interim mitigation, turn off Bluetooth on affected audio devices when not in use and avoid accepting connections from untrusted nearby devices. Since there is no public PoC or known exploitation, this can be triaged as a reliability issue rather than an urgent security threat, but it should be queued for remediation in any connected-audio fleet.
| Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware | v3.x and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.