Junglewise Threat Intelligence

CVE-2026-47148: Silicon Labs EmberZNet denial of service in GetGroupMembership command

CVE-2026-47148 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet, a software stack used for Zigbee wireless networking in smart home and industrial IoT devices, contains a vulnerability that can cause devices to crash. An attacker who has already gained access to the Zigbee network can send a specially crafted message that forces the device to restart or stop functioning. This results in a denial-of-service, potentially disrupting smart home automation or industrial monitoring systems.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Silicon Labs EmberZNet v9.0.2 and earlier within the handling of the Zigbee 'Groups' cluster. A malformed 'GetGroupMembership' command can trigger repeated reads past the end of the message payload, leading to a process termination (denial-of-service). The attack requires the sender to be a device already authenticated and joined to the Zigbee network (PR:L). While the vulnerability involves an out-of-bounds read, no information leakage back to the attacker has been observed. Only devices supporting the Groups cluster are affected.

Affected products

  • Silicon Labs EmberZNet v9.0.2 and earlier

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats