Input validation error in JieLi products - CVE-2021-31611
Published: September 6, 2021
AC690X
AC692X
BT Audio Receiver
XY-WRBT Module
JieLi
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the Bluetooth Classic implementation does not properly handle the reception of an out-of-order LMP Setup procedure (c.f., Figure 1) followed by a malformed LMP packet. A remote attacker in radio range can pass specially crafted input to the application and perform a denial of service (DoS) attack.