CVE-2026-37100
Unauthorized BLE Access in Yamaha SR-B30A Sound Bar Firmware
Publication date: 2026-04-16
Last updated on: 2026-04-18
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| yamaha | sr-b30a | 2.40 |
| yamaha | sound_bar_remote | 2.40 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware version 2.40 and its associated mobile app Sound Bar Remote version 2.40. It allows remote attackers who are within BLE radio range to connect to the device without any authentication by exploiting the Sound Bar Remote protocol.
How can this vulnerability impact me? :
An attacker within Bluetooth range can connect to the Yamaha SR-B30A sound bar without authentication. This unauthorized access could potentially allow the attacker to control the device or interfere with its normal operation.