Out-of-Bounds Write Vulnerability in EmberZNet Door Lock Schedule by Silicon Labs
CVE-2026-47151

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-47151?

In EmberZNet versions prior to 9.0.2, an out-of-bounds write issue can occur when malformed ClearWeekdaySchedule messages are processed. These messages must originate from devices already authenticated to the network and are limited to those supporting the Door Lock cluster. This vulnerability poses a risk of unintended modifications to the Door Lock's schedule state, warranting attention from users and system administrators.

Affected Version(s)

EmberZNet 0 <= 9.0.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University
.