Executive brief
The RS9116W and SiWx917 are wireless connectivity modules used in IoT and embedded devices. An attacker can send an unencrypted pause encryption request message to cause the device to stop responding, resulting in a denial of service that affects device availability and operations.
Technical details
This vulnerability involves a denial of service condition triggered by an unencrypted 'pause encryption request' message in the RS9116W and SiWx917 wireless modules. The root cause appears to be insufficient validation of encryption state before processing pause requests. An attacker with network access can send a crafted unencrypted message to trigger the denial of service condition. The vulnerability is documented as B-E10 in related research. No patch information is currently available based on the advisory text.
Affected products
- Silicon Labs RS9116W
- Silicon Labs SiWx917
Timeline
- 2026-09-08: disclosed