Malformed Color Control Messages Vulnerability in Silicon Labs EmberZNet
CVE-2026-47145
7.1HIGH
What is CVE-2026-47145?
In the affected versions of EmberZNet, a security flaw exists where malformed Color Control messages can trigger asserts that result in process termination. These messages must originate from devices that have already joined the network. The vulnerability poses a risk primarily to devices that support the Color Control cluster, allowing potential disruptions in service.
Affected Version(s)
EmberZNet 0 <= 9.0.2
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University
