CVE-2026-37100: Medium severity Yamaha SR-B30A sound bar firmware vulnerability
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-37100?
CVE-2026-37100 has a high severity rating due to its potential to allow unauthorized remote access.
How do I fix CVE-2026-37100?
To fix CVE-2026-37100, update the Yamaha SR-B30A sound bar firmware to the latest version provided by Yamaha.
Who is affected by CVE-2026-37100?
CVE-2026-37100 affects users of the Yamaha SR-B30A sound bar firmware version 2.40 and the Sound Bar Remote mobile app version 2.40.
What can attackers do with CVE-2026-37100?
Attackers can connect to the affected Yamaha sound bar without authentication, potentially compromising the device.
Is there a workaround for CVE-2026-37100?
Disabling Bluetooth on the Yamaha SR-B30A sound bar can act as a temporary workaround to mitigate the risk associated with CVE-2026-37100.