Description
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bluetooth re‑pairing with an existing paired device can be performed at a lower security level than the originally negotiated level. The vulnerability allows an attacker to re‑establish a connection with reduced encryption or authentication strength, potentially enabling eavesdropping, modification of data, or other malicious actions on the link. The flaw is a classic example of Improper Authorization (CWE‑290) where an authorized device can drop to a less secure protocol state without consumer permission.

Affected Systems

The issue affects Silabs WiseConnect devices based on the RS9116W and SiWx91x chip families. No specific firmware or version numbers are listed, so all releases of these products should be considered potentially vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity risk. EPSS data is not provided, so the likelihood of exploitation is inconclusive, though the vulnerability is publicized and research papers (BLERP) confirm its viability. The attack vector is inferred to be Bluetooth, requiring access to the wireless channel or proximity to the target device. The vulnerability is not yet listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 13, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Silabs documentation for a firmware update that addresses the lower‑security re‑pairing issue and apply it if available.
  • If an update is not yet released, disable the ability to re‑pair with lower security levels through device configuration or permanently disable the Bluetooth interface.
  • Monitor Bluetooth traffic for anomalous re‑pairing attempts and enforce higher security levels by rejecting connections that would downgrade security.

Generated by OpenCVE AI on August 13, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
Title Bluetooth re-pairing can use a lower security level than previous
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:01:52.758Z

Reserved: 2026-08-07T16:20:57.991Z

Link: CVE-2026-19291

cve-icon Vulnrichment

Updated: 2026-08-13T17:01:48.727Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:37.603

Modified: 2026-08-13T15:19:37.603

Link: CVE-2026-19291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:45:03Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing