CVE-2026-19292

Summary

Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.

Affected Software

VendorProductVersion RangeStatus
silabs.comWiseConnect4.0.0 < 4.1.0affected
silabs.comWiseConnect2.0.0 < 2.14.0affected

Weaknesses

  • CWE-305: CWE-305 Authentication bypass by primary weakness

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References