CVE-2026-65932: CWE-440 Expected behavior violation in silabs.com BT122
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
AI Analysis
Technical Summary
The BT122 module from silabs.com contains a vulnerability identified as CVE-2026-65932, categorized under CWE-440 (Expected Behavior Violation). The issue arises when the module receives a plaintext 'pause encryption response' message, which causes it to stop advertising. This leads to a denial of service condition, disrupting normal operation. The CVSS 4.0 base score is 5.3, reflecting a medium severity with attack vector as adjacent network and no privileges or user interaction required. No vendor advisory or patch information is currently available.
Potential Impact
The vulnerability results in a denial of service by causing the BT122 module to cease advertising upon receipt of a specific plaintext message. This disrupts the device's normal functionality and could impact systems relying on its Bluetooth advertising capabilities. There is no indication of privilege escalation, data confidentiality, or integrity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should monitor vendor communications for updates. No specific mitigations or workarounds have been provided by the vendor at this time.
CVE-2026-65932: CWE-440 Expected behavior violation in silabs.com BT122
Description
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
CVSS v4.0
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The BT122 module from silabs.com contains a vulnerability identified as CVE-2026-65932, categorized under CWE-440 (Expected Behavior Violation). The issue arises when the module receives a plaintext 'pause encryption response' message, which causes it to stop advertising. This leads to a denial of service condition, disrupting normal operation. The CVSS 4.0 base score is 5.3, reflecting a medium severity with attack vector as adjacent network and no privileges or user interaction required. No vendor advisory or patch information is currently available.
Potential Impact
The vulnerability results in a denial of service by causing the BT122 module to cease advertising upon receipt of a specific plaintext message. This disrupts the device's normal functionality and could impact systems relying on its Bluetooth advertising capabilities. There is no indication of privilege escalation, data confidentiality, or integrity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should monitor vendor communications for updates. No specific mitigations or workarounds have been provided by the vendor at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Silabs
- Date Reserved
- 2026-07-23T15:47:23.376Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7ddec8bf8831d5395cfffc
Added to database: 08/13/2026, 15:12:08 UTC
Last enriched: 08/13/2026, 15:42:56 UTC
Last updated: 08/13/2026, 17:53:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.