Junglewise Threat Intelligence

CVE-2026-79376: Bestechnic BES2300 L2CAP denial of service

CVE-2026-79376 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Bestechnic BES2300. Vendors: Bestechnic.

Executive brief

Bestechnic BES2300 is a Bluetooth audio system-on-chip (SoC) used in wireless audio devices. A vulnerability in its firmware allows an attacker to send a specially crafted Bluetooth packet that causes the device to crash or become unresponsive, disrupting audio services and requiring device restart.

Technical details

The vulnerability exists in the l2cap_handle_data() function within the BES2300 Bluetooth audio SoC firmware version 3.x and earlier. It is triggered by receiving a malformed L2CAP (Logical Link Control and Adaptation Protocol) packet over a Bluetooth connection. An attacker within Bluetooth range can send the crafted packet without requiring prior authentication or pairing. Successful exploitation results in a denial of service condition, causing the audio device to hang or reset. The vulnerability is classified as a memory handling or input validation flaw in the L2CAP packet processing logic.

Affected products

  • Bestechnic BES2300 3.x and earlier

Timeline

  • 2026-09-08: disclosed

References

Related threats