Junglewise Threat Intelligence

CVE-2026-4526: Silicon Labs EmberZNet out-of-bounds read in ZCL parsing logic

CVE-2026-4526 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet, a software stack used for Zigbee wireless networking, contains a vulnerability that can cause devices to crash. An attacker who has already gained access to the Zigbee network can send a specially crafted message that forces the device to restart or stop functioning. This results in a denial-of-service, potentially disrupting smart home or industrial automation systems, though no data theft has been observed.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the framework parsing logic of Silicon Labs EmberZNet versions 9.0.2 and earlier. The flaw is triggered by malformed global Zigbee Cluster Library (ZCL) messages. An attacker must be authenticated (already joined to the Zigbee network) to deliver the payload via the network. Successful exploitation results in the termination of the process (Denial of Service), but does not result in information leakage or unauthorized data access. Users are advised to monitor Silicon Labs' Simplicity SDK releases for patches.

Affected products

  • Silicon Labs EmberZNet 0 to 9.0.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats