Bluetooth LE Legacy Pairing Bypass in RS9116W and SiWx917 Products by Silicon Labs
CVE-2026-65935

7.6HIGH

Key Information:

Vendor

Silabs.com

Vendor
CVE Published:
13 August 2026

What is CVE-2026-65935?

A vulnerability exists in the RS9116W and SiWx917 Bluetooth LE modules that allows an attacker to bypass the passkey entry mechanism during legacy pairing. This is accomplished by manipulating the temporary key value, potentially leading to unauthorized access or data interception. Organizations using these products should review their security posture and consider implementing mitigations as outlined in vendor resources.

Affected Version(s)

WiseConnect 2.0.0 <= 2.*.*

WiseConnect 4.0.0 <= 4.*.*

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.