Sceawere

Vulnerability Detail

CVE-2026-19291UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bluetooth Re-Pairing Lower Security Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
6h ago
Vendor
silabs.com
Product
WiseConnect
Attack Type
CWE-290 Authentication bypass by spoofing
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-13T15:19:37.603Z",
  "pubdate": "2026-08-13T15:19:37.603Z",
  "executiveSummary": "This vulnerability involves a security flaw during the Bluetooth re-pairing process with an existing device, where the system improperly permits the establishment of a lower security level.\nThe affected products include RS9116W and SiWx91x, as identified in the V3 section of the BLERP research paper.\nThe risk implications include potential downgrade attacks, allowing an adversary to bypass stricter security enforcement mechanisms previously established during the initial pairing phase.\nAttack capabilities require an adversary to interact with the Bluetooth communication channel during the re-pairing sequence between the affected device and an existing paired device.\nExploitation requirements include proximity to the target Bluetooth range and the ability to trigger or observe the re-pairing procedure to force or negotiate a degraded security association.",
  "technicalDetails": "The root cause of this vulnerability lies in the state machine and security negotiation logic governing the Bluetooth re-pairing workflow within the affected firmware.\nWhen an existing device initiates a re-pairing procedure, the vulnerable component fails to properly enforce or maintain the previously negotiated higher security level.\nInstead, the protocol implementation permits a fallback or downgrade to a lower security level during the re-pairing handshake.\nThe attack flow proceeds as follows: First, the attacker identifies a target pair involving an RS9116W or SiWx91x device and a legitimate existing device. Second, the attacker induces or waits for a re-pairing event to occur. Third, during the re-pairing handshake, the attacker manipulates or observes the security parameters as outlined in the BLERP paper V3 findings.\nThe affected versions encompass the RS9116W and SiWx91x product lines utilizing the vulnerable Bluetooth firmware stack.\nAuthentication and privilege requirements depend on the specific interaction model of the Bluetooth connection, but typically an attacker within radio frequency range can attempt to influence the pairing negotiation without prior authentication to the lower security tier.\nNetwork exposure is constrained to the local wireless Bluetooth medium, requiring physical proximity to the target hardware.\nThe post-exploitation impact includes the potential circumvention of robust cryptographic protections, enabling subsequent unauthorized access, data interception, or man-in-the-middle attacks facilitated by the weaker security association."
}
CVE-2026-19291: Bluetooth Re-Pairing Lower Security Flaw (HIGH Severity, CVSS: 8.8) - Sceawere