CVE-2024-2104

HIGH

JBL LIVE PRO 2 TWS and TUNE FLEX - Unauthenticated Device Control via BLE GATT Server

Title source: llm
STIX 2.1

Description

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
JBL/LIVE PRO 2 TWS
JBL/TUNE FLEX
Published Dec 10, 2025
Tracked Since Feb 18, 2026