Silicon Labs EmberZNet是美国Silicon Labs公司的一个嵌入式无线网络协议栈软件。 Silicon Labs EmberZNet 9.0.2及之前版本存在缓冲区错误漏洞,该漏洞源于畸形OTA请求导致OTA server解析器越界读取,可能从RAM中读取有限数据并返回给请求者。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Silicon Labs | EmberZNet | ≤ 9.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Silicon Labs | EmberZNet | 0 ~ 9.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47149 | Door Lock GetUserType invalid table index in EmberZNet v9.0.2 | |
| CVE-2026-47154 | Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 | |
| CVE-2026-47152 | Level Control Move divide-by-zero in EmberZNet v9.0.2 | |
| CVE-2026-47151 | Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 | |
| CVE-2026-47145 | Color Control hue/saturation assertion abort in EmberZNet v9.0.2 | |
| CVE-2026-47153 | Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 | |
| CVE-2026-47146 | Color Control color-temperature assertion abort in EmberZNet v9.0.2 | |
| CVE-2026-47148 | Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 | |
| CVE-2026-47150 | IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 | |
| CVE-2026-6432 | Improper bounds validation in EmberZNet SDK | |
| CVE-2026-2815 | Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable k | |
| CVE-2026-4526 | Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 |
No comments yet