CVE-2026-5706
largeOut-of-bounds Write RCE in Silicon Labs Bluetooth Mesh SDK 6.1.4 and Earlier
CVE-2026-5706 is an out-of-bounds write (CWE-130, improper handling of inconsistent structural types) in the packet-parsing code of Silicon Labs Bluetooth Mesh SDK 6.1.4 and earlier, in which malformed extended advertising packets corrupt the stack. To trigger it, an attacker must be within Bluetooth radio range and send a crafted malformed extended advertisement from a device that has already joined the mesh network, so unprovisioned outsiders cannot exploit it directly. Because the write corrupts the stack, a successful attack yields remote code execution with high impact on the confidentiality, integrity, and availability of the affected device. Only devices running this SDK in a provisioner role that supports extended advertisements appear to be impacted; ordinary mesh nodes without that role are not affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% (19th percentile) chance of exploitation in the next 30 days, indicating limited near-term exploitation risk.
What to do: Inventory products built on Bluetooth Mesh SDK 6.1.4 or earlier that act as provisioners with extended-advertisement support and prioritize them for update. Upgrade to a Bluetooth Mesh SDK release newer than 6.1.4 per Silicon Labs' security advisory (check the vendor's product-security page for the fixed version); as an interim mitigation, restrict which provisioned devices can send extended advertisements and limit provisioner functionality where it is not required. No public PoC or known exploitation exists at this time, but re-assess once Silicon Labs publishes fixed releases or exploitation details.
| Silicon Labs Bluetooth Mesh SDK | 6.1.4 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
- Weakness
- CWE-130
- Vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.