CVE-2024-2105 Details
Description
An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.
A denial-of-service vulnerability has been identified in certain JBL Bluetooth speakers due to improper validation of the channel map field in Bluetooth Low Energy (BLE) connection requests. This flaw allows an unauthorized attacker within Bluetooth range to send a specially crafted packet that causes the device to crash or enter a deadlock state, disrupting music playback and disconnecting active connections. Recovery from this state requires a manual reboot of the device, as automatic reconnection is not possible.
As of now, no fix is available for this vulnerability. Users must manually reboot their devices to restore normal operation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 10, 2025CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2025-089 | [email protected] | AdvisoryVendor |
| https://harman.csaf-tp.certvde.com/.well-known/csaf/white/2025/hbsa-2025-0002.json | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JBL Boombox 2 | All versions |
CPE
Remediation
| |
| JBL Boombox 3 | All versions |
CPE
Remediation
| |
| JBL Flip 5 | All versions |
CPE
Remediation
| |
| JBL Flip 6 | All versions |
CPE
Remediation
| |
| JBL Pulse 4 | All versions |
CPE
Remediation
| |
| JBL Pulse 5 | All versions |
CPE
Remediation
| |
| JBL Xtreme 3 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |
Volerion