CVE-2026-65935 PUBLISHED

Bypassing passkey entry in legacy pairing

Assigner: Silabs
Reserved: 23.07.2026 Published: 13.08.2026 Updated: 13.08.2026

Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.6

Product Status

Vendor silabs.com
Product WiseConnect
Versions Default: unaffected
  • affected from 2.0.0 to 2.*.* (incl.)
  • affected from 4.0.0 to 4.*.* (incl.)

References

Problem Types

  • CWE-305 Authentication bypass by primary weakness CWE

Impacts

  • CAPEC-115 Authentication Bypass