CVE-2026-65935

Summary

Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.

Affected Software

VendorProductVersion RangeStatus
silabs.comWiseConnect2.0.0 <= 2.*.*affected
silabs.comWiseConnect4.0.0 <= 4.*.*affected

Weaknesses

  • CWE-305: CWE-305 Authentication bypass by primary weakness

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References