Junglewise Threat Intelligence

CVE-2026-47147: Silicon Labs EmberZNet out-of-bounds read in OTA server parser

CVE-2026-47147 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet, a software stack used for Zigbee networking in smart home and industrial IoT devices, contains a vulnerability in its Over-the-Air (OTA) update component. An attacker with access to the local wireless network can send specially crafted update requests to trigger a memory error. This can lead to the exposure of small amounts of internal device memory or cause the device to become unresponsive, potentially disrupting smart home operations or industrial monitoring.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the OTA server parser of Silicon Labs EmberZNet versions 9.0.2 and earlier. The flaw is triggered when the OTA server processes malformed OTA requests. An attacker who has already joined the Zigbee network can exploit this to read a limited amount of data from RAM or potentially cause a crash (denial of service). The impact is restricted to devices supporting the OTA Server cluster, and the location/size of the leaked data is constrained by the parser logic. Users are advised to update to a version beyond 9.0.2.

Affected products

  • Silicon Labs EmberZNet 0 to 9.0.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats