Junglewise Threat Intelligence

CVE-2026-47151: Silicon Labs EmberZNet out-of-bounds write in Door Lock cluster

CVE-2026-47151 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet, a software stack used for Zigbee networking in smart home and industrial devices, contains a vulnerability in its door lock management component. An attacker with access to the local Zigbee network can send specially crafted messages to crash or disrupt the scheduling functionality of electronic door locks. This could lead to a denial of service where lock schedules cannot be properly managed or updated.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Silicon Labs EmberZNet v9.0.2 and earlier within the Door Lock cluster. The flaw is triggered by malformed ClearWeekdaySchedule messages, which cause the stack to write data outside of the intended Door Lock schedule state buffer. While the size and location of the write are limited, it can lead to memory corruption or a denial of service (system crash). Exploitation requires the attacker to be on a device that has already successfully joined the Zigbee network (PR:L). Only devices implementing the Door Lock cluster are affected.

Affected products

  • Silicon Labs EmberZNet v9.0.2 and earlier

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats