MEDIUM

CVE-2026-47153

Silabs Emberznet 2026-06-25 CVSS v3.1
CVSS
6.5

Description

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

Summary dbcve.org

A divide-by-zero fault occurs in EmberZNet's Level Control cluster when processing a malformed Level Control Step command. The vulnerability is exploitable only by devices that have already joined the network, making it a network-adjacent attack requiring authentication. Successful exploitation causes the process to terminate, resulting in denial of service.

Mitigation

Update EmberZNet to the latest version containing the patch. Network segmentation and strict join controls can limit exposure until patches are applied. Only devices implementing the Level Control cluster are affected.

Weakness (CWE)

CWE-369

EPSS Score

0.44%
Probability of exploitation in next 30 days
37.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE