Executive brief
Silicon Labs EmberZNet, a software framework used for Zigbee wireless networking in smart home and industrial IoT devices, contains a vulnerability in its security sensor management. An attacker with a device already connected to the network can send a specially crafted message to crash the system. This results in a loss of connectivity and requires a device restart, potentially disrupting security monitoring or automation services.
Technical details
An out-of-bounds (OOB) write vulnerability exists in Silicon Labs EmberZNet v9.0.2 and earlier within the handling of Intruder Alarm System (IAS) Zone enrollment messages. The root cause is a failure to properly validate malformed enrollment messages, which triggers an OOB write to the state-table. While the size and location of the write are limited, it is sufficient to terminate the process (Denial of Service). Exploitation requires the attacker to be using a device that has already successfully joined the Zigbee network (PR:L) and targets devices supporting the IAS Zone cluster. Silicon Labs has addressed this in newer releases of the Simplicity SDK / EmberZNet.
Affected products
- Silicon Labs EmberZNet v9.0.2 and earlier
Timeline
- 2026-06-25: advisory: Initial disclosure by Silicon Labs