Junglewise Threat Intelligence

CVE-2026-6432: Silicon Labs EmberZNet SDK improper bounds validation

CVE-2026-6432 · Severity: info · CVSS 5.3 · Published 2026-06-25

Vendors: Silicon Labs.

Executive brief

A vulnerability exists in the Silicon Labs EmberZNet SDK, a software development kit used to build Zigbee-based smart home and industrial IoT devices. An attacker could exploit this flaw to cause affected devices to crash or leak internal memory information. This could lead to service disruptions or the exposure of sensitive data handled by the connected device.

Technical details

The vulnerability is classified as CWE-130 (Improper Handling of Length Parameter Inconsistency) within the EmberZNet SDK. It stems from improper bounds validation when processing input, which can lead to an out-of-bounds condition. An attacker with low privileges can exploit this over a network to trigger a denial-of-service (crash) or leak dynamic memory contents. The issue affects versions 9.0.2 and earlier of the SDK, which is part of the Silicon Labs SiSDK (Simplicity SDK).

Affected products

  • Silicon Labs EmberZNet SDK (SiSDK) 9.0.2 and earlier

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References