CVE-2026-16101: forced re-pairing with already bonded device
Published Aug 13, 2026
·Updated
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
Event History
Aug 13, 2026
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16101?
The severity of CVE-2026-16101 is rated high with a score of 8.8.
2
What vulnerabilities are associated with CVE-2026-16101?
CVE-2026-16101 involves spoofing an already bonded device to force re-pairing with a rogue device.
3
How do I fix CVE-2026-16101?
To mitigate CVE-2026-16101, implement authentication and validation measures for device pairing.
4
What devices are impacted by CVE-2026-16101?
CVE-2026-16101 affects the RS9116W and SiWx917 devices.
5
What are the risks of CVE-2026-16101?
The risk associated with CVE-2026-16101 includes potential unauthorized access and data compromise due to forced re-pairing.