CVE-2026-19291
Received Received - Intake

Bluetooth Re-Pairing Weak Security in RS9116W and SiWx91x

Vulnerability report for CVE-2026-19291, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Silicon Graphics (SGI)

Description

Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
silicon_labs siwx91x_bluetooth_le_sdk 4.1.0
silicon_labs rs9116_bluetooth_le_sdk 2.14.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Bluetooth Low Energy (BLE) re-pairing with an existing device using a lower security level. It affects Silicon Labs' RS9116W and SiWx91x devices. Attackers can exploit this to downgrade security during re-pairing, enabling impersonation or Man-in-the-Middle attacks with minimal user interaction.

Detection Guidance

This vulnerability involves Bluetooth Low Energy (BLE) re-pairing attacks. Detection requires monitoring BLE pairing processes for security level downgrades or unauthenticated re-pairing attempts. Use tools like Wireshark with BLE protocol analyzers to inspect SMP security request messages. Check for devices repeatedly disconnecting and reconnecting with weaker encryption. No specific commands are provided in the resources.

Impact Analysis

An attacker could intercept or manipulate data transmitted between your device and a paired BLE device. This may lead to unauthorized access, data theft, or control over your device if it relies on BLE for sensitive operations like authentication or communication.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by enabling unauthorized access to personal or health data transmitted over BLE. Organizations using affected devices may fail to meet encryption and security standards mandated by these regulations.

Mitigation Strategies

Update affected Silicon Labs BLE SDKs to versions 4.1.0 or later. For SiWx91x devices, use the `rsi_ble_vendor_set_SMP_min_enc_keysize` API to enforce minimum encryption key sizes between 7 and 16 bytes. Ensure all BLE devices use the latest firmware with security patches. Disable unnecessary BLE features if updates are unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19291. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart