Sceawere

Vulnerability Detail

CVE-2026-16101UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RS9116W and SiWx917 Device Spoofing Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
6h ago
Vendor
silabs.com
Product
WiseConnect
Attack Type
CWE-290 Authentication bypass by spoofing
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-13T15:19:33.347Z",
  "pubdate": "2026-08-13T15:19:33.347Z",
  "executiveSummary": "This security analysis addresses a device spoofing and forced re-pairing vulnerability affecting the Silicon Labs RS9116W and SiWx917 wireless devices, as identified in the BLERP research paper (V1). The vulnerability involves the cryptographic bonding and pairing mechanisms implemented within the affected products. Specifically, an unauthorized adversary capable of spoofing a previously bonded legitimate device can forcefully trigger a re-pairing or re-bonding sequence with a rogue device under the attacker's control.\nThe primary impact of this vulnerability is the compromise of established trust relationships between legitimate endpoints, potentially leading to unauthorized access, man-in-the-middle (MitM) conditions, or interception of sensitive data transmitted over the wireless medium. The affected systems encompass the RS9116W and SiWx917 hardware platforms and their associated firmware implementations responsible for handling pairing and bonding logic.\nThe risk implications are significant for environments relying on these wireless chips for secure Internet of Things (IoT) communication, as an attacker with proximity and spoofing capabilities can bypass existing authentication states. Exploitation requires the attacker to possess the capability to spoof identifiers of an already bonded device to initiate the malicious re-pairing sequence. No specific patch versions or CVE identifiers are provided in the input context, necessitating strict adherence to standard cryptographic hardening and protocol verification practices.",
  "technicalDetails": "The vulnerability resides within the pairing and bonding state machine of the RS9116W and SiWx917 wireless chipsets. Rooted in how the devices handle reconnection requests and identity verification for previously bonded peripherals or centrals, the implementation fails to sufficiently validate the legitimacy of re-pairing initiations when presented with a spoofed MAC address or device identifier matching an existing bond.\nThe attack flow begins when an attacker observes or intercepts legitimate communication between an RS9116W or SiWx917 device and its bonded peer. The attacker then crafts a spoofed advertisement or connection request mimicking the valid bonded device. Upon receiving this spoofed frame, the vulnerable RS9116W or SiWx917 firmware improperly handles the collision or state transition, dropping or invalidating the current cryptographic trust state and initiating a new pairing procedure with the rogue device.\nExploitation requires the attacker to be within radio frequency (RF) range of the target to transmit the spoofed frames. The vulnerability exploits the lack of robust cryptographic challenge-response validation prior to tearing down or overwriting an existing valid security association. Because the device prioritizes or automatically accepts the re-initiation sequence from what it assumes is a returning trusted device, it exposes itself to unauthorized association without requiring out-of-band user confirmation or secondary authentication factors.\nThe vulnerable components include the firmware modules responsible for Bluetooth/Wi-Fi link layer management, security manager protocols, and bonding database state handlers. Post-exploitation impact includes the rogue device successfully bonding with the victim hardware, enabling subsequent eavesdropping, injection of malicious payloads, or complete control over the established communication channel, thereby undermining the confidentiality and integrity guarantees provided by the initial pairing phase."
}
CVE-2026-16101: RS9116W and SiWx917 Device Spoofing Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere