Executive brief
Silicon Labs EmberZNet, a software suite used to develop Zigbee-based smart home and industrial IoT devices, is vulnerable to a flaw that can cause devices to crash. An attacker with a device already connected to the network can send a specifically crafted command that forces the target device to restart or stop functioning. This results in a loss of service for the affected smart devices until they are recovered.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in Silicon Labs EmberZNet versions v9.0.2 and earlier within the handling of Zigbee Level Control cluster commands. Specifically, a malformed 'Level Control Move' command can trigger a process termination due to a mathematical error during processing. An attacker must already have a device joined to the Zigbee network (PR:L) to issue the command. The impact is limited to a denial-of-service (DoS) of the affected process on devices supporting the Level Control cluster. Users are advised to monitor Silicon Labs releases for patches following v9.0.2.
Affected products
- Silicon Labs EmberZNet v9.0.2 and earlier
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory