Junglewise Threat Intelligence

CVE-2026-47149: Silicon Labs EmberZNet out-of-bounds read in Door Lock cluster

CVE-2026-47149 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet, a software stack used for Zigbee networking in smart home and industrial devices, contains a flaw in how it handles door lock commands. An authorized device on the network can send a specially crafted message that causes the receiving device to crash. This results in a denial-of-service, potentially rendering smart locks or connected controllers unresponsive until they are restarted.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Silicon Labs EmberZNet versions v9.0.2 and earlier within the Door Lock cluster implementation. The flaw is triggered when the stack processes malformed or out-of-range Door Lock user identifiers. An attacker must already be a member of the Zigbee network (authenticated) to send the malicious message. Successful exploitation results in a process termination (denial-of-service), though no information leakage or data exfiltration has been observed. The vulnerability specifically impacts devices supporting the Door Lock cluster.

Affected products

  • Silicon Labs EmberZNet v9.0.2 and earlier

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats