Junglewise Threat Intelligence

CVE-2026-3290: Silicon Labs RS9116 predictable HRNG values in power save mode

CVE-2026-3290 · Severity: info · CVSS 7.4 · Published 2026-05-14

Vendors: Silicon Labs.

Executive brief

A security issue exists in the Silicon Labs RS9116 Wi-Fi and Bluetooth module, which is commonly used in IoT devices. When the device is in power-saving mode, the component responsible for generating random numbers produces predictable results. This could allow an attacker to bypass security protections, potentially leading to the interception of private communications or unauthorized access to the device.

Technical details

A vulnerability exists in the Hardware Random Number Generator (HRNG) of the Silicon Labs RS9116 Wi-Fi/Bluetooth solution. When power save mode is active, timing limitations within the HRNG hardware result in insufficient entropy, leading to the generation of predictable random values (CWE-332). An attacker within adjacent network range could exploit this predictability to compromise cryptographic protocols that rely on the HRNG for nonces, keys, or salts. This could result in high confidentiality and integrity impacts. The issue is addressed in the WiseConnect Wi-Fi/BT SDK.

Affected products

  • Silicon Labs RS9116 Wi-Fi/Bluetooth SDK All versions prior to fix

Timeline

  • 2026-05-14: advisory: NVD publication date

References