Description
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
Published: 2026-08-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A re-pairing process with a legitimate device can be performed at a lower security level than the original pairing. The lower level reduces the strength of the Long Term Key, making it easier for an attacker to brute force the key. This weakness is defined as CWE‑305, reflecting improper handling of security settings during re‑authentication.

Affected Systems

Silicon Labs WiseConnect devices are affected. No specific firmware or hardware revisions are listed in the CNA data; only the product line is identified.

Risk and Exploitability

The CVSS score of 8.8 indicates a high impact when the flaw is exploited. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a Bluetooth connection; an adversary who can initiate or force a re‑pairing session with a legitimate device can exploit the downgrade to perform a brute‑force attack on the LTK. Because the flaw reduces cryptographic strength rather than creating a new attack surface, the overall risk remains high for any device using legacy pairing protocols.

Generated by OpenCVE AI on August 13, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version that contains the fix for the Bluetooth re‑pairing downgrade flaw as described in Silicon Labs release notes.
  • Configure the Bluetooth stack to disallow legacy pairing or enforce high‑security pairing during re‑authentication.
  • Monitor Bluetooth pairing logs for unusual re‑pairing attempts and block devices that use lower security levels until patched.

Generated by OpenCVE AI on August 13, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com wiseconnect
Vendors & Products Silabs.com
Silabs.com wiseconnect

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
Title Bluetooth re-pairing with legitimate device can use lower security level
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Silabs.com Wiseconnect
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:03:49.758Z

Reserved: 2026-08-07T16:21:05.493Z

Link: CVE-2026-19292

cve-icon Vulnrichment

Updated: 2026-08-13T17:03:07.661Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:37.737

Modified: 2026-08-13T18:17:23.617

Link: CVE-2026-19292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:28Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness