CVE-2024-2104 Details
Description
Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.
A vulnerability exists in the JBL LIVE PRO 2 TWS and JBL TUNE FLEX headphones due to improper Bluetooth Low Energy (BLE) security configurations and a lack of authentication on the GATT server. This allows adjacent, unauthenticated attackers to read and write device control commands through the mobile app service, potentially rendering the device unusable. Exploitation could also lead to unauthorized code execution by allowing attackers to send altered firmware updates, as detailed in the Harman CSAF advisory HBSA-2025-0001.
There is no known remediation at this moment.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 10, 2025CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2024-076 | [email protected] | AdvisoryVendor |
| https://harman.csaf-tp.certvde.com/.well-known/csaf/white/2025/hbsa-2025-0001.json | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Harman JBL LIVE PRO 2 TWS | All versions |
CPE
Remediation
| |
| Harman JBL TUNE FLEX | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |
Volerion