CVE-2026-79379
Deferred Deferred - Pending Action

Buffer Overflow in Bestechnic BES2300 Bluetooth Audio SoC Firmware

Vulnerability report for CVE-2026-79379, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: MITRE

Description

A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted frame.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bestechnic_co_ltd bes2300_firmware to 5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier. It allows attackers to cause a Denial of Service (DoS) by sending a crafted frame. The issue stems from a race condition in bounds checking, enabling manipulation of SBC frame parameters and RTP frame_num spoofing.

Detection Guidance

Detection requires monitoring for crashes or watchdog reboots in BES2300 devices running firmware v3.x or earlier. Check system logs for SBC decoder errors or unexpected reboots. No specific commands are provided in the resources.

Impact Analysis

The vulnerability can cause a system crash leading to a Denial of Service (DoS). An attacker could trigger an infinite loop and watchdog reboot by rapidly switching configurations or using high bitpool values in dual-channel mode. This disrupts normal device operation until a reboot occurs.

Mitigation Strategies
  • Upgrade BES2300 firmware to v5.0 or later, as no patches exist for legacy versions.
  • If upgrading is not possible, restrict SBC decoding to trusted sources or disable A2DP Sink functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79379. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart