MEDIUM

CVE-2026-6432

2026-06-25 CVSS v4.0
CVSS
5.3

Description

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

Summary dbcve.org

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier allows an attacker to trigger crashes or cause dynamic memory leakage, likely through malformed Zigbee network packets or API calls that do not properly validate array or buffer boundaries before memory operations.

Mitigation

Upgrade EmberZNet SDK to version 9.0.3 or later if available; otherwise, audit code paths that handle external input and add explicit bounds checks before memory read/write operations.

Weakness (CWE)

CWE-130

EPSS Score

0.4%
Probability of exploitation in next 30 days
33.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE