MEDIUM
CVE-2026-47152
CVSS
6.5
Description
In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
Summary dbcve.org
A malformed Level Control Move command sent from an authenticated device in EmberZNet v9.0.2 and earlier triggers a divide-by-zero fault, causing process termination. Only devices supporting the Level Control cluster are impacted by this denial-of-service vulnerability.
Mitigation
Upgrade to a patched version of EmberZNet beyond v9.0.2 that includes proper input validation for Level Control Move commands to prevent the divide-by-zero condition.
Weakness (CWE)
CWE-369
EPSS Score
0.44%
Probability of exploitation in next 30 days
37.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.