CVE-2021-31612 is a medium-severity vulnerability affecting Zhuhai Jieli AC690X devices, where a flaw in the Bluetooth Classic implementation allows an attacker to trigger a deadlock. This occurs when an oversized LMP packet, exceeding 17 bytes, is received during the LMP auto rate procedure. The attack requires physical proximity (radio range) and no user interaction, leading to a denial of service. There is no evidence of active exploitation, nor are there public exploit modules available, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zh-jieli:ac6901_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zh-jieli:ac690n_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zh-jieli:ac692n_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zh-jieli:ac6902_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zh-jieli:ac6903_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.