CVE-2021-28155 is a denial-of-service vulnerability affecting JBL TUNE500BT devices, stemming from improper handling of continuous unsolicited LMP responses in their Bluetooth Classic implementation. An attacker within radio range can exploit this by flooding the device with LMP Feature Response data, causing it to shut down. This medium-severity vulnerability (CVSS 6.5) requires adjacent network access and no user interaction, leading to high availability impact. There is no evidence of active exploitation, nor is public exploit code available, though it has garnered some community discussion and media coverage as part of broader Bluetooth vulnerability disclosures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:jbl:tune500bt_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.