Junglewise Threat Intelligence

CVE-2026-47146: Silicon Labs EmberZNet denial of service in Color Control cluster

CVE-2026-47146 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

A vulnerability in Silicon Labs EmberZNet software, which is used to manage Zigbee wireless networks, could allow an attacker to crash connected devices. By sending a specially crafted message related to color lighting controls, an attacker can force a device to shut down or restart. This could lead to a loss of control over smart lighting systems or other connected hardware until the devices are recovered.

Technical details

A reachable assertion vulnerability (CWE-617) exists in Silicon Labs EmberZNet versions 9.0.2 and earlier. The flaw is triggered when the software processes malformed Color Control cluster messages, causing an internal 'assert' to fail and terminating the execution process. An attacker must already have a device joined to the Zigbee network (low privileges) to send these messages. Successful exploitation results in a denial-of-service (DoS) for devices supporting the Color Control cluster. The vulnerability is reachable over the network without user interaction.

Affected products

  • Silicon Labs EmberZNet 0 through 9.0.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats