Description
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. 
See vulnerability B-E3 in the related paper below.
Published: 2026-08-13
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an attacker to skip the required passkey during Bluetooth LE legacy pairing by altering the temporary key value. This violation of the expected authentication protocol means a malicious device can pair without user consent, potentially gaining privileged access to the target’s services or data. The weakness is classified as a compromised authentication process.

Affected Systems

The vulnerability affects Silabs WiseConnect devices that use the RS9116W or SiWx917 chipsets. These chips are used in various low‑power IoT applications that rely on BLE legacy pairing for initial setup or maintenance.

Risk and Exploitability

The CVSS score of 7.6 marks this as high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers would need proximity to the target device’s wireless interface to manipulate the temporary key over BLE. Once successful, the attacker can pair and create a data channel or execute commands as if a legitimate user had granted the connection.

Generated by OpenCVE AI on August 13, 2026 at 17:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the RS9116W or SiWx917 firmware to the latest version that patches the temporary key manipulation bug
  • Disable Bluetooth LE legacy pairing mode if the device supports it, enforcing secure connections instead
  • If a firmware update is unavailable, consider disabling the Bluetooth radio on the device until a fix can be applied

Generated by OpenCVE AI on August 13, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com wiseconnect
Vendors & Products Silabs.com
Silabs.com wiseconnect

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.
Title Bypassing passkey entry in legacy pairing
Weaknesses CWE-305
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Silabs.com Wiseconnect
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T16:09:20.765Z

Reserved: 2026-07-23T15:47:23.377Z

Link: CVE-2026-65935

cve-icon Vulnrichment

Updated: 2026-08-13T16:09:16.529Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:56.290

Modified: 2026-08-13T16:18:41.570

Link: CVE-2026-65935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:17Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness