Impact
Bluetooth re‑pairing with an existing paired device can be performed at a lower security level than the originally negotiated level. The vulnerability allows an attacker to re‑establish a connection with reduced encryption or authentication strength, potentially enabling eavesdropping, modification of data, or other malicious actions on the link. The flaw is a classic example of Improper Authorization (CWE‑290) where an authorized device can drop to a less secure protocol state without consumer permission.
Affected Systems
The issue affects Silabs WiseConnect devices based on the RS9116W and SiWx91x chip families. No specific firmware or version numbers are listed, so all releases of these products should be considered potentially vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity risk. EPSS data is not provided, so the likelihood of exploitation is inconclusive, though the vulnerability is publicized and research papers (BLERP) confirm its viability. The attack vector is inferred to be Bluetooth, requiring access to the wireless channel or proximity to the target device. The vulnerability is not yet listed in CISA’s KEV catalog.
OpenCVE Enrichment