MEDIUM

CVE-2026-47145

Silabs Emberznet 2026-06-25 CVSS v3.1
CVSS
6.5

Description

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

Summary dbcve.org

In EmberZNet versions 9.0.2 and earlier, the Zigbee ZCL Color Control cluster implementation lacks proper input validation for incoming messages. When a malformed Color Control message is received from an authenticated network device, it triggers an assertion failure that terminates the process, causing a denial of service.

Mitigation

Implement robust input validation and error handling in the Color Control cluster message parser to gracefully handle malformed messages instead of asserting. Additionally, enforce network access controls to prevent unauthorized devices from joining.

Weakness (CWE)

CWE-617 Reachable Assertion

EPSS Score

0.44%
Probability of exploitation in next 30 days
37.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE