Description
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to spoof a device that has already been bonded, forcing the Silabs RS9116W or SiWx917 radio to drop its current bond and re‑pair with a rogue device. The resulting unauthorized pairing permits the attacker to impersonate the legitimate device, potentially injecting or intercepting data over BLE or Wi‑Fi and thus violating confidentiality and integrity. The weakness corresponds to CWE‑290 and carries a CVSS score of 8.8.

Affected Systems

The affected products are Silabs WiseConnect modules RS9116W and SiWx917. No specific firmware versions are listed in the CNA data, so users should check that their device is running the firmware version referenced in the provided release‑notes links.

Risk and Exploitability

The exploit can be performed over the Bluetooth Low Energy channel, typically requiring proximity to the target. EPSS data is not available, but the high CVSS score signals a significant risk. The vulnerability is not currently listed in the CISA KEV catalog, and publicly documented attacks are limited to the academic BLERP paper. Nonetheless, because the flaw permits active impersonation of a bonded device, the risk warrants immediate attention.

Generated by OpenCVE AI on August 13, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the RS9116W firmware to the latest version that includes the patch noted in the release notes.
  • Update the SiWx917 firmware to its latest version containing the same fix.
  • If possible, disable or tightly restrict automatic re‑pairing in the device configuration, or enforce a whitelist of trusted devices to prevent unintended bonding.

Generated by OpenCVE AI on August 13, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
Title forced re-pairing with already bonded device
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:01:15.389Z

Reserved: 2026-07-17T14:36:03.677Z

Link: CVE-2026-16101

cve-icon Vulnrichment

Updated: 2026-08-13T17:01:11.826Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:33.347

Modified: 2026-08-13T15:19:33.347

Link: CVE-2026-16101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:30:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing