Executive brief
Silicon Labs EmberZNet, a software stack used for Zigbee wireless networking in smart home and industrial IoT devices, is vulnerable to a denial-of-service attack. An attacker with access to the local wireless network can send a specifically crafted command that causes the device to crash. This results in the device becoming unresponsive, potentially disrupting smart home automation or industrial monitoring systems.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in Silicon Labs EmberZNet versions v9.0.2 and earlier. The flaw is triggered by a malformed 'Level Control Step' command sent to devices supporting the Level Control cluster. An attacker must be authenticated to the Zigbee network (PR:L) to deliver the payload. Successful exploitation results in a process crash, causing a denial of service on the affected IoT device. The vulnerability is reachable over the network via standard Zigbee communication protocols.
Affected products
- Silicon Labs EmberZNet v9.0.2 and earlier
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory