Zigbee Router Vulnerability in Silicon Labs Product Line
CVE-2025-7964
9.2CRITICAL
What is CVE-2025-7964?
A vulnerability exists within Silicon Labs' Zigbee Router that is triggered by malformed 802.15.4 MAC Data Requests. Upon receiving such a request, the Zigbee Coordinator incorrectly sends a ânetwork leaveâ command to the Zigbee Router. This flaw causes the router to enter a non-rejoinable state, preventing connected end devices from rejoining the network if no suitable parent device is available. Recovery from this state necessitates manual recommissioning of the Zigbee Router, which can disrupt network operations and affect connected IoT devices.
Affected Version(s)
Silicon Labs Zigbee Stack 0 <= 4.4.6
Silicon Labs Zigbee Stack 0 <= 2025.6.1
