CVE-2024-2105: Jbl Boombox 2
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.
Affected products
- Jbl Boombox 2: any version
- Jbl Boombox 3: any version
- Jbl Flip 5: any version
- Jbl Flip 6: any version
- Jbl Pulse 4: any version
- Jbl Pulse 5: any version
- Jbl Xtreme 3: any version
Published 2025-12-10. Last modified 2026-06-17.