ZeroHour

CVE-2026-5706

large

Out-of-bounds Write RCE in Silicon Labs Bluetooth Mesh SDK 6.1.4 and Earlier

CVSS 4.0
8.9 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-5706 is an out-of-bounds write (CWE-130, improper handling of inconsistent structural types) in the packet-parsing code of Silicon Labs Bluetooth Mesh SDK 6.1.4 and earlier, in which malformed extended advertising packets corrupt the stack. To trigger it, an attacker must be within Bluetooth radio range and send a crafted malformed extended advertisement from a device that has already joined the mesh network, so unprovisioned outsiders cannot exploit it directly. Because the write corrupts the stack, a successful attack yields remote code execution with high impact on the confidentiality, integrity, and availability of the affected device. Only devices running this SDK in a provisioner role that supports extended advertisements appear to be impacted; ordinary mesh nodes without that role are not affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% (19th percentile) chance of exploitation in the next 30 days, indicating limited near-term exploitation risk.

What to do: Inventory products built on Bluetooth Mesh SDK 6.1.4 or earlier that act as provisioners with extended-advertisement support and prioritize them for update. Upgrade to a Bluetooth Mesh SDK release newer than 6.1.4 per Silicon Labs' security advisory (check the vendor's product-security page for the fixed version); as an interim mitigation, restrict which provisioned devices can send extended advertisements and limit provisioner functionality where it is not required. No public PoC or known exploitation exists at this time, but re-assess once Silicon Labs publishes fixed releases or exploitation details.

Affected
Silicon Labs Bluetooth Mesh SDK6.1.4 and earlier
Estimated exposure
largelow hundreds of thousands of Bluetooth Mesh devices/provisioner deployments worldwide (order-of-magnitude estimate) — Silicon Labs is a leading Bluetooth LE SoC vendor whose Bluetooth Mesh SDK is widely embedded in commercial lighting, building-automation, and consumer IoT deployments, but the impacted role is limited to provisioners supporting extended…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.

Weakness
CWE-130
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.