CVE-2019-19194 describes a critical vulnerability in Telink Semiconductor BLE SDK versions prior to November 2019, affecting TLSR8x5x, TLSR823x, and TLSR826x devices. This flaw allows an attacker within radio range to establish an encrypted session with a zero long-term key (LTK) by sending an out-of-order link-layer encryption request during Secure Connections pairing. The vulnerability has a CVSS score of 8.8 (HIGH), indicating high impact on confidentiality, integrity, and availability, with a low attack complexity and no user interaction required. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.4.0CPE matchmatch criteria | cpe:2.3:a:telink-semi:tlsr8258_ble_sdk:*:*:*:*:*:*:*:* | ||
<= 3.3CPE matchmatch criteria | cpe:2.3:a:telink-semi:tlsr8269_ble_sdk:*:*:*:*:*:*:*:* | ||
<= 3.4.0CPE matchmatch criteria | cpe:2.3:a:telink-semi:tlsr8253_ble_sdk:*:*:*:*:*:*:*:* | ||
<= 3.4.0CPE matchmatch criteria | cpe:2.3:a:telink-semi:tlsr8251_ble_sdk:*:*:*:*:*:*:*:* | ||
<= 1.3.0CPE matchmatch criteria | cpe:2.3:a:telink-semi:tlsr8232_ble_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.