Description
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A re-pairing process with a legitimate device can be performed at a lower security level than the original pairing. The lower level reduces the strength of the Long Term Key, making it easier for an attacker to brute force the key. This weakness is defined as CWE‑305, reflecting improper handling of security settings during re‑authentication.

Affected Systems

Silicon Labs WiseConnect devices are affected. No specific firmware or hardware revisions are listed in the CNA data; only the product line is identified.

Risk and Exploitability

The CVSS score of 8.8 indicates a high impact when the flaw is exploited. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a Bluetooth connection; an adversary who can initiate or force a re‑pairing session with a legitimate device can exploit the downgrade to perform a brute‑force attack on the LTK. Because the flaw reduces cryptographic strength rather than creating a new attack surface, the overall risk remains high for any device using legacy pairing protocols.

Generated by OpenCVE AI on August 13, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version that contains the fix for the Bluetooth re‑pairing downgrade flaw as described in Silicon Labs release notes.
  • Configure the Bluetooth stack to disallow legacy pairing or enforce high‑security pairing during re‑authentication.
  • Monitor Bluetooth pairing logs for unusual re‑pairing attempts and block devices that use lower security levels until patched.

Generated by OpenCVE AI on August 13, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
Title Bluetooth re-pairing with legitimate device can use lower security level
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T14:17:18.403Z

Reserved: 2026-08-07T16:21:05.493Z

Link: CVE-2026-19292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:37.737

Modified: 2026-08-13T15:19:37.737

Link: CVE-2026-19292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:30:04Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness