CVE-2026-16769: CWE-440 Expected behavior violation in silabs.com WiseCnnect
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-16769) in silabs.com WiseCnnect version 2.0.0 arises from an unencrypted 'pause encryption request' message that causes a denial of service condition in the RS9116W/SiWx917 modules. It is classified as a CWE-440 expected behavior violation. The CVSS 4.0 score is 7.1, indicating high severity, with attack vector as adjacent network, low attack complexity, and no privileges or user interaction required. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation results in denial of service, disrupting normal operation of the affected RS9116W/SiWx917 modules. The vulnerability does not require privileges or user interaction and can be triggered from an adjacent network, making it a significant availability risk for systems using the affected version.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, consider limiting access to the affected modules from adjacent networks to reduce exposure.
CVE-2026-16769: CWE-440 Expected behavior violation in silabs.com WiseCnnect
Description
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
CVSS v4.0
Score 7.1high
Affected software
pkg:github/silabs.com/WiseCnnectRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-16769) in silabs.com WiseCnnect version 2.0.0 arises from an unencrypted 'pause encryption request' message that causes a denial of service condition in the RS9116W/SiWx917 modules. It is classified as a CWE-440 expected behavior violation. The CVSS 4.0 score is 7.1, indicating high severity, with attack vector as adjacent network, low attack complexity, and no privileges or user interaction required. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation results in denial of service, disrupting normal operation of the affected RS9116W/SiWx917 modules. The vulnerability does not require privileges or user interaction and can be triggered from an adjacent network, making it a significant availability risk for systems using the affected version.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, consider limiting access to the affected modules from adjacent networks to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Silabs
- Date Reserved
- 2026-07-23T15:53:43.587Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa032dbacd9273b49e3e66e
Added to database: 09/08/2026, 16:07:55 UTC
Last enriched: 09/08/2026, 16:22:06 UTC
Last updated: 09/09/2026, 01:15:31 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.