CVE-2026-5706
Received
Received - Intake
Bluetooth Mesh SDK Out-of-Bounds Write Leading to RCE
Vulnerability report for CVE-2026-5706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-28
Last updated on: 2026-08-28
Assigner: Silicon Graphics (SGI)
Description
Description
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siliconlabs | bluetooth_mesh_sdk | 6.1.4 |
| siliconlabs | gecko_sdk | From 4.2.6 (inc) to 4.5.1 (inc) |
| silicon_labs | bluetooth_mesh_sdk | to 6.1.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-130 | The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data. |