CVE-2024-2104: Jbl Live Pro 2 Tws

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.

Affected products

  • Jbl Live Pro 2 Tws: any version
  • Jbl Tune Flex: any version

Published 2025-12-10. Last modified 2026-06-17.