CVE-2026-47149
Description
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.
Summary dbcve.org
In EmberZNet Zigbee stack versions 9.0.2 and earlier, the Door Lock cluster implementation lacks proper bounds validation when processing user identifiers. Crafted messages with out-of-range user IDs cause the stack to read beyond allocated table boundaries, triggering a fatal exception that terminates the process. Exploitation requires an already-authenticated device on the network to send malformed Door Lock commands, resulting in denial of service for the affected lock device.
Mitigation
Deploy the vendor-supplied EmberZNet firmware update addressing bounds checking in the Door Lock cluster. Until patched, isolate Door Lock devices on a dedicated network segment and monitor for anomalous device behavior to detect exploitation attempts.