Search Results (6 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16101 1 Silabs.com 1 Wiseconnect 2026-08-14 8.8 High
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
CVE-2026-19291 1 Silabs.com 1 Wiseconnect 2026-08-14 8.8 High
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
CVE-2026-19292 1 Silabs.com 1 Wiseconnect 2026-08-14 8.8 High
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
CVE-2026-19293 1 Silabs.com 1 Wiseconnect 2026-08-14 8.8 High
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
CVE-2026-65935 1 Silabs.com 1 Wiseconnect 2026-08-14 N/A
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.
CVE-2026-65936 1 Silabs.com 1 Wiseconnect 2026-08-14 N/A
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.