CVE-2026-47146
Description
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
Summary dbcve.org
In EmberZNet Zigbee stack versions 9.0.2 and earlier, specially crafted malformed Color Control cluster messages trigger assertion failures that crash the process. An attacker must have a previously authenticated device on the network to send these malicious packets, making this a network-adjacent denial-of-service vulnerability affecting only devices implementing the Color Control cluster.
Mitigation
Apply the EmberZNet vendor patch for this vulnerability and update all affected devices to the patched firmware version. Network segmentation and monitoring for anomalous Color Control messages can provide interim detection capability.