CVE-2026-16769
largeUnauthenticated DoS in Silicon Labs RS9116W/SiWx917 Wi-Fi chips
Silicon Labs' RS9116W and SiWx917 wireless chips mishandle an unencrypted 'pause encryption request' message (CWE-440, expected behavior violation), which causes a denial of service on the affected device. An attacker within radio range of the target (CVSS adjacent-network vector) can send this unauthenticated message with no privileges or user interaction required. The attacker gains only disruption: the CVSS 4.0 score of 7.1 (high) reflects a high availability impact with no confidentiality or integrity impact, meaning the device's Wi-Fi connectivity can be knocked out but no data is exposed or altered. Operators of end products that embed these Silicon Labs chips — typically IoT, industrial, or consumer devices with Wi-Fi connectivity — are affected. There is no public proof-of-concept, the EPSS score is very low (0.1%, 1st percentile), the flaw is not in CISA KEV, and it was identified through security research (vulnerability B-E10 in the related paper), so no exploitation is known.
What to do: Update the RS9116W and SiWx917 firmware on affected end products to the latest Silicon Labs release that addresses CVE-2026-16769, checking the Silicon Labs security advisory for the specific fixed firmware versions (none are given in the source data). Inventory which of your products embed these chips and verify their chip firmware versions. Because exploitation requires an attacker within radio range and there is no known exploitation or public PoC, prioritizing updates for devices deployed in accessible Wi-Fi environments is a reasonable triage approach.
| Silicon Labs RS9116W Wi-Fi module | — |
| Silicon Labs SiWx917 Wi-Fi/BLE SoC | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
- Weakness
- CWE-440
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.