Executive brief
Silicon Labs EmberZNet, a software stack used for Zigbee networking in smart home and industrial devices, contains a flaw in how it handles door lock commands. An authorized device on the network can send a specially crafted message that causes the receiving device to crash. This results in a denial-of-service, potentially rendering smart locks or connected controllers unresponsive until they are restarted.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Silicon Labs EmberZNet versions v9.0.2 and earlier within the Door Lock cluster implementation. The flaw is triggered when the stack processes malformed or out-of-range Door Lock user identifiers. An attacker must already be a member of the Zigbee network (authenticated) to send the malicious message. Successful exploitation results in a process termination (denial-of-service), though no information leakage or data exfiltration has been observed. The vulnerability specifically impacts devices supporting the Door Lock cluster.
Affected products
- Silicon Labs EmberZNet v9.0.2 and earlier
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory