{"id":"CVE-2026-5706","title":"In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution","summary":"In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network…","severity":"none","cwe":["CWE-130"],"published":"2026-08-28","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5706","references":[{"url":"https://github.com/SiliconLabs/gecko_sdk/releases","label":"product-security@silabs.com"},{"url":"https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm000000Et6HIAS?operationContext=S1","label":"product-security@silabs.com"}],"tags":["nvd"],"epss":0.00266,"epssPercentile":0.18999,"ingestedAt":"2026-09-08T20:10:03.159Z","slug":"CVE-2026-5706","body":"## Overview\n\nIn Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}