CVE-2026-47153
Description
In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
Summary dbcve.org
A divide-by-zero fault occurs in EmberZNet's Level Control cluster when processing a malformed Level Control Step command. The vulnerability is exploitable only by devices that have already joined the network, making it a network-adjacent attack requiring authentication. Successful exploitation causes the process to terminate, resulting in denial of service.
Mitigation
Update EmberZNet to the latest version containing the patch. Network segmentation and strict join controls can limit exposure until patches are applied. Only devices implementing the Level Control cluster are affected.