CVE-2026-79377: Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware vulnerability
Published Sep 8, 2026
·Updated
A heap overflow in the a2dpdecodersbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
Affected Software
1 affected component
Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware<=3.x
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which devices are exposed to this issue?
Devices using Bestechnic BES2300 Bluetooth Audio SoC firmware version 3.x or earlier are affected. Exposure requires that the vulnerable Bluetooth audio firmware is present on the device.
2
What does an attacker need to exploit the flaw?
An attacker needs to send a crafted L2CAP packet to the affected device. The provided information does not state whether pairing, authentication, or proximity requirements apply.
3
What is the known impact of successful exploitation?
Successful exploitation can cause a denial of service through a heap overflow in the a2dp_decoder_sbc.cpp component.