CVE-2026-19293: Silabs.com Wiseconnect
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
Affected products
- Silabs.com Wiseconnect: from 4.0.0, before 4.1.0 (fixed in 4.1.0); from 2.0.0, before 2.14.0 (fixed in 2.14.0)
Published 2026-08-13. Last modified 2026-09-08.