CVE-2026-65936: CWE-126 Buffer over-read in silabs.com WiseConnect
CVE-2026-65936 is a medium severity vulnerability in silabs.com WiseConnect affecting versions 2.0.0 and 4.0.0. It involves a buffer over-read (CWE-126) triggered by a malformed Bluetooth connection request message, which can cause the RS9116W/SiWx917 devices to leak potentially sensitive information. There is no official patch or remediation level provided yet, and no known exploits in the wild have been reported.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-65936) in silabs.com WiseConnect arises from a buffer over-read condition (CWE-126) when processing malformed Bluetooth connection request messages. The affected devices, RS9116W and SiWx917, may leak sensitive information due to this flaw. The CVSS 4.0 base score is 5.3, indicating medium severity with attack vector as adjacent network and no privileges or user interaction required. The vulnerability is confirmed in versions 2.0.0 and 4.0.0 of WiseConnect. No vendor advisory or patch information is currently available.
Potential Impact
Successful exploitation of this vulnerability can lead to leakage of potentially sensitive information from the affected devices. The attack requires an adjacent network attacker and does not require privileges or user interaction. The impact is limited to information disclosure without further escalation or system compromise indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround has been published by silabs.com at this time.
CVE-2026-65936: CWE-126 Buffer over-read in silabs.com WiseConnect
Description
CVE-2026-65936 is a medium severity vulnerability in silabs.com WiseConnect affecting versions 2.0.0 and 4.0.0. It involves a buffer over-read (CWE-126) triggered by a malformed Bluetooth connection request message, which can cause the RS9116W/SiWx917 devices to leak potentially sensitive information. There is no official patch or remediation level provided yet, and no known exploits in the wild have been reported.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/silabs.com/WiseConnectRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-65936) in silabs.com WiseConnect arises from a buffer over-read condition (CWE-126) when processing malformed Bluetooth connection request messages. The affected devices, RS9116W and SiWx917, may leak sensitive information due to this flaw. The CVSS 4.0 base score is 5.3, indicating medium severity with attack vector as adjacent network and no privileges or user interaction required. The vulnerability is confirmed in versions 2.0.0 and 4.0.0 of WiseConnect. No vendor advisory or patch information is currently available.
Potential Impact
Successful exploitation of this vulnerability can lead to leakage of potentially sensitive information from the affected devices. The attack requires an adjacent network attacker and does not require privileges or user interaction. The impact is limited to information disclosure without further escalation or system compromise indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround has been published by silabs.com at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Silabs
- Date Reserved
- 2026-07-23T15:47:23.377Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7ddec8bf8831d5395d000c
Added to database: 08/13/2026, 15:12:08 UTC
Last enriched: 08/13/2026, 15:42:24 UTC
Last updated: 08/13/2026, 15:42:24 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.