CVE-2026-5706
8.9Silicon Labs · BT Mesh SDK
A vulnerability in the Silicon Labs BT Mesh SDK allows remote code execution via malformed extended advertisements, requiring an already joined device to trigger.
Executive summary
A critical vulnerability in the Silicon Labs BT Mesh SDK allows remote code execution through out of bounds writes, posing a significant risk to network integrity.
Vulnerability
This flaw involves an out of bounds write (CWE-787) triggered by malformed extended advertisements, which can lead to stack corruption and remote code execution. Although the attack requires the sender to be an authenticated member of the mesh network, the impact is severe as it allows for unauthorized code execution on the provisioner.
Business impact
The potential for remote code execution represents a severe security risk that could lead to full system compromise of the affected mesh provisioner. With a CVSS score of 8.9, this vulnerability is classified as high severity, indicating that successful exploitation could result in unauthorized control of network infrastructure and potential data exfiltration.
Remediation
Immediate Action: Organizations should review the Silicon Labs GitHub repository and official security advisories to identify and apply the latest firmware or SDK patches that resolve these memory safety issues.
Proactive Monitoring: Security teams should monitor internal network traffic for anomalous or malformed Bluetooth advertisement packets that deviate from standard protocol specifications.
Compensating Controls: Restrict physical and logical access to the mesh network to trusted, verified devices only, as the vulnerability requires the attacker to have already joined the network.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, this vulnerability demands immediate attention from engineering and security teams managing Bluetooth Mesh deployments. Ensure that all provisioners are updated to versions beyond 6.1.4 or 9.1.0 as soon as the vendor provides the necessary patches to prevent exploitation of the stack corruption vulnerability.