Junglewise Threat Intelligence

CVE-2025-12131: Silicon Labs 802.15.4 stack denial of service via truncated packet

CVE-2025-12131 · Severity: medium · CVSS 6.5 · Published 2026-02-05

Vendors: Silicon Labs.

Executive brief

Silicon Labs' 802.15.4 wireless networking stack processes packets used in IoT and industrial applications. A malformed truncated packet can trigger an assertion failure in the stack, crashing the affected device or service and causing a temporary denial of service. This vulnerability could disrupt wireless communication in networks relying on 802.15.4 connectivity.

Technical details

The vulnerability is an assertion failure triggered by processing a truncated 802.15.4 frame. The affected component does not properly validate packet length before dereferencing packet data, causing an assert when encountering a malformed frame below the minimum expected size. An attacker with network access to the 802.15.4 network can send a crafted truncated packet to trigger the assertion. Successful exploitation results in denial of service through application or device crash. Patches addressing the input validation flaw are available from Silicon Labs.

Affected products

  • Silicon Labs 802.15.4 Stack

Timeline

  • 2026-02-05: disclosed

References