Junglewise Threat Intelligence

CVE-2026-16769: Silicon Labs RS9116W/SiWx917 denial of service via unencrypted pause request

CVE-2026-16769 · Severity: info · Published 2026-09-08

Vendors: Silicon Labs.

Executive brief

The RS9116W and SiWx917 are wireless connectivity modules used in IoT and embedded devices. An attacker can send an unencrypted pause encryption request message to cause the device to stop responding, resulting in a denial of service that affects device availability and operations.

Technical details

This vulnerability involves a denial of service condition triggered by an unencrypted 'pause encryption request' message in the RS9116W and SiWx917 wireless modules. The root cause appears to be insufficient validation of encryption state before processing pause requests. An attacker with network access can send a crafted unencrypted message to trigger the denial of service condition. The vulnerability is documented as B-E10 in related research. No patch information is currently available based on the advisory text.

Affected products

  • Silicon Labs RS9116W
  • Silicon Labs SiWx917

Timeline

  • 2026-09-08: disclosed

References