Junglewise Threat Intelligence

CVE-2026-79378: Bestechnic BES2300 Bluetooth SoC denial of service in L2CAP handler

CVE-2026-79378 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Bestechnic BES2300. Vendors: Bestechnic.

Executive brief

Bestechnic's BES2300 is a Bluetooth Audio System-on-Chip used in wireless audio devices such as earbuds and headphones. A vulnerability in the firmware's L2CAP (Logical Link Control and Adaptation Protocol) handler allows an attacker within Bluetooth range to crash the device or temporarily disable its audio functionality by sending a specially crafted packet, causing service disruption for users.

Technical details

The vulnerability exists in the btm_acl_handle() function of BES2300 firmware v3.x and earlier, which processes Bluetooth L2CAP packets. An attacker can send a crafted L2CAP packet over the Bluetooth network that triggers an unhandled error condition, causing a denial of service (crash or hang). The attack requires Bluetooth network proximity but no authentication or user interaction. This affects the availability of Bluetooth audio services on affected devices.

Affected products

  • Bestechnic BES2300 v3.x and earlier

Timeline

  • 2026-09-08: disclosed

References

Related threats