CVE-2026-16101
Received Received - Intake

Spoofing Attack Forces Re-Pairing in RS9116W and SiWx917

Vulnerability report for CVE-2026-16101, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Silicon Graphics (SGI)

Description

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
silicon_labs siwx91x_bluetooth_le_sdk to 4.1.0 (exc)
silicon_labs rs9116_bluetooth_le_sdk 2.14.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16101 is a Bluetooth Low Energy (BLE) re-pairing vulnerability affecting Silicon Labs SiWx91x and RS9116W devices. An attacker can spoof a bonded device to force a re-pairing process with a rogue device, potentially allowing unauthorized access or data interception.

Impact Analysis

This vulnerability enables impersonation and Man-in-the-Middle attacks. Attackers could intercept or manipulate BLE communications, leading to unauthorized access to sensitive data or control of paired devices. The impact includes potential data breaches or device hijacking.

Mitigation Strategies

Update the Silicon Labs SiWx91x Bluetooth LE SDK to version 4.1.0 or later. Use the rsi_ble_vendor_set_SMP_min_enc_keysize API to enforce minimum encryption key sizes between 7 and 16 bytes during BLE pairing processes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16101. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart