Malformed Color Control Messages Vulnerability in Silicon Labs EmberZNet
CVE-2026-47145

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-47145?

In the affected versions of EmberZNet, a security flaw exists where malformed Color Control messages can trigger asserts that result in process termination. These messages must originate from devices that have already joined the network. The vulnerability poses a risk primarily to devices that support the Color Control cluster, allowing potential disruptions in service.

Affected Version(s)

EmberZNet 0 <= 9.0.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University
.