Bluetooth LE Legacy Pairing Bypass in RS9116W and SiWx917 Products by Silicon Labs
CVE-2026-65935
7.6HIGH
What is CVE-2026-65935?
A vulnerability exists in the RS9116W and SiWx917 Bluetooth LE modules that allows an attacker to bypass the passkey entry mechanism during legacy pairing. This is accomplished by manipulating the temporary key value, potentially leading to unauthorized access or data interception. Organizations using these products should review their security posture and consider implementing mitigations as outlined in vendor resources.
Affected Version(s)
WiseConnect 2.0.0 <= 2.*.*
WiseConnect 4.0.0 <= 4.*.*
