CVE-2026-5706
Received Received - Intake

Bluetooth Mesh SDK Out-of-Bounds Write Leading to RCE

Vulnerability report for CVE-2026-5706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: Silicon Graphics (SGI)

Description

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
siliconlabs bluetooth_mesh_sdk 6.1.4
siliconlabs gecko_sdk From 4.2.6 (inc) to 4.5.1 (inc)
silicon_labs bluetooth_mesh_sdk to 6.1.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves malformed extended advertisements in Bluetooth Mesh SDK 6.1.4 and earlier. These malformed messages can cause out-of-bounds writes, leading to stack corruption and potential remote code execution. The attack requires the malicious device to already be part of the network, and only provisioners supporting extended advertisements are affected.

Detection Guidance

Detection requires monitoring for malformed extended advertisements in Bluetooth Mesh networks. Use Bluetooth sniffing tools like Wireshark with Bluetooth Mesh dissector or Silicon Labs' proprietary tools to capture and analyze advertisement packets. Check for unusual stack behavior or crashes in provisioners after receiving extended advertisements.

Impact Analysis

If you use a vulnerable Bluetooth Mesh SDK version, an attacker within range could exploit this flaw to execute arbitrary code on your device. This could allow them to take control of the system, steal data, or disrupt operations. Only systems using extended advertisements and already joined to the network are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected SDKs must address this flaw to maintain data protection and security standards.

Mitigation Strategies

Update Bluetooth Mesh SDK to version 6.1.5 or later to address the out-of-bounds write issue in extended advertisements. Ensure only trusted devices join the network and disable extended advertisement support if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart