CVE-2026-5706

8.9

Silicon Labs · BT Mesh SDK

A vulnerability in the Silicon Labs BT Mesh SDK allows remote code execution via malformed extended advertisements, requiring an already joined device to trigger.

Executive summary

A critical vulnerability in the Silicon Labs BT Mesh SDK allows remote code execution through out of bounds writes, posing a significant risk to network integrity.

Vulnerability

This flaw involves an out of bounds write (CWE-787) triggered by malformed extended advertisements, which can lead to stack corruption and remote code execution. Although the attack requires the sender to be an authenticated member of the mesh network, the impact is severe as it allows for unauthorized code execution on the provisioner.

Business impact

The potential for remote code execution represents a severe security risk that could lead to full system compromise of the affected mesh provisioner. With a CVSS score of 8.9, this vulnerability is classified as high severity, indicating that successful exploitation could result in unauthorized control of network infrastructure and potential data exfiltration.

Remediation

Immediate Action: Organizations should review the Silicon Labs GitHub repository and official security advisories to identify and apply the latest firmware or SDK patches that resolve these memory safety issues.

Proactive Monitoring: Security teams should monitor internal network traffic for anomalous or malformed Bluetooth advertisement packets that deviate from standard protocol specifications.

Compensating Controls: Restrict physical and logical access to the mesh network to trusted, verified devices only, as the vulnerability requires the attacker to have already joined the network.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution, this vulnerability demands immediate attention from engineering and security teams managing Bluetooth Mesh deployments. Ensure that all provisioners are updated to versions beyond 6.1.4 or 9.1.0 as soon as the vendor provides the necessary patches to prevent exploitation of the stack corruption vulnerability.

More Silicon Labs CVEs

Sources