CVE-2021-31611

MEDIUM

Zhuhai Jieli AC690X and AC692X Firmware - Denial of Service via Malformed LMP Packet

Title source: llm
STIX 2.1

Description

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order LMP Setup procedure that is followed by a malformed LMP packet, allowing attackers in radio range to deadlock a device via a crafted LMP packet. The user needs to manually reboot the device to restore communication.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
http://www.zh-jieli.com/product/68-cn.html
Third Party Advisory x_refsource_misc
https://launchstudio.bluetooth.com/ListingDetails/58628
Third Party Advisory x_refsource_misc
https://launchstudio.bluetooth.com/ListingDetails/19746

Scores

CVSS v3 5.7
EPSS 0.0035
EPSS Percentile 27.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-667
Status published
Products (5)
zh-jieli/ac6901_firmware
zh-jieli/ac6921_firmware
zh-jieli/ac6925_firmware
zh-jieli/ac6926_firmware
zh-jieli/ac6928_firmware
Published Sep 07, 2021
Tracked Since Feb 18, 2026