CVE-2026-16101

Summary

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

Affected Software

VendorProductVersion RangeStatus
silabs.comWiseConnect4.0.0 < 4.1.0affected
silabs.comWiseConnect2.0.0 < 2.14.0affected

Weaknesses

  • CWE-290: CWE-290 Authentication bypass by spoofing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References