Junglewise Threat Intelligence

CVE-2026-17610: Silicon Labs SiSDK denial of service in multiprotocol mode

CVE-2026-17610 · Severity: info · Published 2026-08-28

Vendors: Silicon Labs.

Executive brief

SiSDK is a software development kit used to develop applications for Silicon Labs wireless microcontroller devices. Under high network traffic loads, a dropped ACK (acknowledgment packet) can cause a denial of service condition in devices running concurrent Zigbee and Thread protocols, potentially disrupting IoT and smart home deployments that rely on these wireless protocols.

Technical details

This is a denial of service vulnerability affecting SiSDK v2026.6.0 and earlier that manifests when EFR32MG24 and EFR32MG26 devices operate in multiprotocol mode with concurrent Zigbee and Thread enabled. The root cause is improper handling of network ACKs under high traffic loads, leading to dropped acknowledgments. The vulnerability is triggered by network conditions (high traffic) and is reachable to any entity that can generate sustained network traffic toward the affected device. Attackers can cause service interruptions on vulnerable wireless networks. Patches are expected in later versions of SiSDK.

Affected products

  • Silicon Labs SiSDK 2026.6.0 and earlier
  • Silicon Labs EFR32MG24 running concurrent multiprotocol Zigbee and Thread
  • Silicon Labs EFR32MG26 running concurrent multiprotocol Zigbee and Thread

Timeline

  • 2026-08-28: disclosed: CVE-2026-17610 published

References

Related threats