Junglewise Threat Intelligence

CVE-2026-47145: Silicon Labs EmberZNet denial of service in Color Control cluster

CVE-2026-47145 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

A vulnerability in Silicon Labs EmberZNet software, which is used to manage Zigbee wireless networks, could allow an attacker to crash connected devices. By sending a specially crafted message related to color lighting controls, an attacker who has already gained access to the network can force a device to shut down or restart. This results in a loss of control over smart lighting or other Zigbee-enabled hardware until the system is recovered.

Technical details

A Reachable Assertion (CWE-617) exists in Silicon Labs EmberZNet versions up to and including v9.0.2 within the Color Control cluster implementation. An attacker with low privileges (already joined to the Zigbee network) can send malformed Color Control messages to a target device. If the device supports the Color Control cluster, the malformed input triggers an internal software assertion, causing the process to terminate and resulting in a denial of service (DoS). The vulnerability is reachable over the network without user interaction, provided the attacker is an authenticated node on the network.

Affected products

  • Silicon Labs EmberZNet v9.0.2 and earlier

Timeline

  • 2026-06-25: disclosed: Initial NVD publication date
  • 2026-06-25: advisory: Silicon Labs advisory released

References

Related threats