Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Silicon Labs — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting Silicon Labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Silicon Labs designs microcontrollers, wireless connectivity solutions, and analog integrated circuits primarily for industrial, automotive, and consumer IoT applications. With thirty-one recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has frequently involved remote code execution and buffer overflow flaws within its wireless stack and development tools. These vulnerabilities often stem from insufficient input validation in embedded firmware or misconfigured default credentials in debugging interfaces. While no catastrophic, widespread data breaches have been publicly attributed to the vendor, the nature of its hardware-centric products means that exploited flaws can potentially compromise physical device integrity or enable unauthorized network access. Security updates are typically distributed via firmware patches, requiring careful integration by downstream manufacturers to mitigate risks associated with legacy components and unpatched wireless protocols.

CVE ID Title CVSS Severity Published
CVE-2026-15419 CP210x Driver Memory Corruption results in Arbitrary Code Execution — silabser.sys driver CWE-121 7.0 High 2026-09-10
CVE-2026-15418 CP210x Memory Leakage — silabser.sys driver CWE-130 2.4 Low 2026-09-10
CVE-2026-15417 CP210x Denial of Service — silabser.sys driver CWE-369 6.9 Medium 2026-09-10
CVE-2026-17610 RAIL 802.15.4 Mux missing ACK can lead to DoS — SiSDK CWE-404 6.0 Medium 2026-08-27
CVE-2026-5706 Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements — BT Mesh SDK CWE-130 8.9 High 2026-08-27
CVE-2026-6924 Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path — Silicon Labs Matter Github CWE-336 8.7 High 2026-07-23
CVE-2026-6432 Improper bounds validation in EmberZNet SDK — SiSDK CWE-130 - - 2026-06-25
CVE-2026-47154 Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 — EmberZNet CWE-125 - - 2026-06-25
CVE-2026-47153 Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 — EmberZNet CWE-369 - - 2026-06-25
CVE-2026-47152 Level Control Move divide-by-zero in EmberZNet v9.0.2 — EmberZNet CWE-369 - - 2026-06-25
CVE-2026-47151 Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 — EmberZNet CWE-787 - - 2026-06-25
CVE-2026-47150 IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 — EmberZNet CWE-787 - - 2026-06-25
CVE-2026-47149 Door Lock GetUserType invalid table index in EmberZNet v9.0.2 — EmberZNet CWE-125 - - 2026-06-25
CVE-2026-47148 Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 — EmberZNet CWE-125 - - 2026-06-25
CVE-2026-47147 OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2 — EmberZNet CWE-125 - - 2026-06-25
CVE-2026-47146 Color Control color-temperature assertion abort in EmberZNet v9.0.2 — EmberZNet CWE-617 - - 2026-06-25
CVE-2026-47145 Color Control hue/saturation assertion abort in EmberZNet v9.0.2 — EmberZNet CWE-617 - - 2026-06-25
CVE-2026-4526 Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 — EmberZNet CWE-125 - - 2026-06-25
CVE-2026-2815 Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys — SiSDK CWE-339 - - 2026-06-25
CVE-2026-3290 Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values — RS9116 SDK CWE-332 - - 2026-05-14
CVE-2025-2838 Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability — Gecko OS CWE-835 6.5AI Medium AI 2025-03-26
CVE-2025-2837 Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability — Gecko OS CWE-121 8.8AI High AI 2025-03-26
CVE-2024-9055 DPA Countermeasures need reseeding — Simplicity SDK CWE-331 4.2 Medium 2025-03-17
CVE-2024-12975 Silicon Labs CPC can leak information in full duplex SPI — Simplicity SDK CWE-126 6.5 - 2025-03-07
CVE-2024-23937 Silicon Labs Gecko OS Debug Interface Format String — Gecko OS CWE-200 4.3 Medium 2025-01-31
CVE-2024-23973 Silicon Labs Gecko OS HTTP GET Request Handling Stack-based Buffer Overflow — Gecko OS CWE-120 8.8 High 2025-01-30
CVE-2024-24731 Silicon Labs Gecko OS http_download Stack-based Buffer Overflow — Gecko OS CWE-120 7.5 High 2025-01-30
CVE-2024-23938 Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability — Gecko OS CWE-121 8.8 High 2024-09-28
CVE-2023-41093 Loss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuse — Simplicity SDK CWE-416 3.1 Low 2024-07-12
CVE-2024-22472 Long S0 frames received by 500 series Z-Wave devices may cause buffer overflow — Z-Wave SDK CWE-120 8.1 High 2024-05-07

This page lists every published CVE security advisory associated with Silicon Labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.