Junglewise Threat Intelligence

CVE-2026-47154: Silicon Labs EmberZNet out-of-bounds read in Simple Metering cluster

CVE-2026-47154 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Silicon Labs EmberZNet. Vendors: Silicon Labs.

Executive brief

Silicon Labs EmberZNet is a software stack used in Zigbee wireless networking devices, such as smart meters and home automation hubs. A vulnerability in how the software handles specific metering messages allows an attacker with access to the network to crash the device. This results in a denial-of-service, potentially disrupting utility monitoring or smart home operations, though no data is leaked.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Silicon Labs EmberZNet versions 9.0.2 and earlier. The flaw is triggered during the iteration of interval entries within a malformed GetProfileResponse message, specifically affecting devices supporting the Simple Metering cluster. An attacker must already have joined the Zigbee network (PR:L) to send the malicious message. Successful exploitation results in process termination (denial-of-service), though no information leakage or data corruption was observed during analysis. The vulnerability is addressed in newer releases of the Simplicity SDK/EmberZNet stack.

Affected products

  • Silicon Labs EmberZNet 0 to 9.0.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats