By vendor
Silabs vulnerabilities
Known CVEs affecting Silabs products, prioritized by severity, with SEC.co remediation and detection guidance.
10 published vulnerabilities
- CVE-2026-47150HIGH 7.1
EmberZNet, Silicon Labs' Zigbee networking stack, contains a flaw in how it processes enrollment messages from the IAS (Intruder Alarm System) Zone cluster. A device already connected to the network can send specially crafted enrollment packets that cause the software to write data beyond the intended boundaries of a state table, crashing the process. The vulnerability is confined to network-adjacent attackers with prior network membership and only affects devices that implement IAS Zone functionality.
- CVE-2026-47151HIGH 7.1
CVE-2026-47151 is a memory safety vulnerability in Silicon Labs' EmberZNet v9.0.2 and earlier that allows an authenticated network attacker to corrupt Door Lock cluster state by sending specially crafted schedule messages. An attacker who has already joined the Zigbee network can trigger out-of-bounds memory writes, potentially disabling or malfunctioning door lock scheduling features. The vulnerability is contained to devices implementing the Door Lock cluster and does not permit remote code execution, but it can degrade the availability and integrity of lock functionality.
- CVE-2026-4526MEDIUM 6.5
EmberZNet, Silicon Labs' Zigbee networking framework, contains a vulnerability in versions 9.0.2 and earlier that allows an already-connected network device to crash the framework by sending specially crafted global ZCL (Zigbee Cluster Library) messages. The vulnerability does not expose sensitive data and requires the attacker to already have network access—it is primarily a denial-of-service risk rather than a confidentiality or integrity threat.
- CVE-2026-47145MEDIUM 6.5
EmberZNet versions 9.0.2 and earlier contain a vulnerability where specially crafted Color Control messages can crash the application. The attack requires the attacker to already be a joined member of the network, limiting exposure to internal threats. Only devices that support the Color Control cluster are vulnerable. The impact is denial of service—the application terminates unexpectedly—rather than data theft or system compromise.
- CVE-2026-47146MEDIUM 6.5
CVE-2026-47146 is a denial-of-service vulnerability in Silicon Labs EmberZNet versions 9.0.2 and earlier. An attacker who has already joined a Zigbee network can send specially crafted Color Control cluster messages that cause the EmberZNet process to crash. The vulnerability is limited to devices that implement the Color Control cluster, and requires the attacker to be an authenticated network member—not an external threat.
- CVE-2026-47148MEDIUM 6.5
EmberZNet versions 9.0.2 and earlier contain a denial-of-service vulnerability triggered by malformed GetGroupMembership commands. An attacker with network access and prior device enrollment can send a specially crafted message that causes the receiving device to read past the end of its message buffer, crashing the process. The vulnerability does not leak data and only affects devices that support the Groups cluster—a subset of EmberZNet deployments.
- CVE-2026-47149MEDIUM 6.5
EmberZNet v9.0.2 and earlier contains a flaw where specially crafted Door Lock cluster messages with invalid user identifiers can crash the affected device. An attacker must already be part of the network and send the malformed message from an authenticated device to trigger the issue. No data is leaked in the attack, but the device becomes unavailable until restarted.
- CVE-2026-47152MEDIUM 6.5
EmberZNet v9.0.2 and earlier contain a denial-of-service vulnerability triggered by a specially crafted Level Control Move command. An attacker with network access and credentials to join the network can send this malformed command to crash the EmberZNet process, disrupting device functionality. The vulnerability only affects devices that implement the Level Control cluster, a component used for controlling brightness, speed, or similar dimming/ramping functions in Zigbee networks.
- CVE-2026-47153MEDIUM 6.5
A flaw in Silicon Labs EmberZNet v9.0.2 and earlier allows a network-joined device to crash the software through a specially crafted Level Control Step command. The vulnerability stems from a divide-by-zero error that terminates the process. Because the attacker must already be part of the network and the target device must support Level Control (a lighting/dimming feature in Zigbee), the exposure is narrower than an unauthenticated internet attack, but still represents a denial-of-service risk in IoT and smart-home deployments.
- CVE-2026-47154MEDIUM 6.5
EmberZNet versions up to 9.0.2 contain a vulnerability where specially crafted meter response messages can crash devices that support the Simple Metering cluster. The vulnerability only affects devices already connected to the network, and an attacker would need network access and authentication to send the malicious message. No data is stolen or leaked in the attack.