CVE-2026-19293

Summary

SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.

Affected Software

VendorProductVersion RangeStatus
silabs.comWiseConnect4.0.0 < 4.1.0affected
silabs.comWiseConnect2.0.0 < 2.14.0affected

Weaknesses

  • CWE-521: CWE-521 Weak password requirements

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References