MEDIUM
CVE-2026-6432
CVSS
5.3
Description
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
Summary dbcve.org
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier allows an attacker to trigger crashes or cause dynamic memory leakage, likely through malformed Zigbee network packets or API calls that do not properly validate array or buffer boundaries before memory operations.
Mitigation
Upgrade EmberZNet SDK to version 9.0.3 or later if available; otherwise, audit code paths that handle external input and add explicit bounds checks before memory read/write operations.
Weakness (CWE)
CWE-130
EPSS Score
0.4%
Probability of exploitation in next 30 days
33.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.