Out-of-Bounds Write Vulnerability in EmberZNet Door Lock Schedule by Silicon Labs
CVE-2026-47151
7.1HIGH
What is CVE-2026-47151?
In EmberZNet versions prior to 9.0.2, an out-of-bounds write issue can occur when malformed ClearWeekdaySchedule messages are processed. These messages must originate from devices already authenticated to the network and are limited to those supporting the Door Lock cluster. This vulnerability poses a risk of unintended modifications to the Door Lock's schedule state, warranting attention from users and system administrators.
Affected Version(s)
EmberZNet 0 <= 9.0.2
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University
