← Vulnerability feed

Vulnerability record · CVE-2026-4526 · published 25 June 2026

CVE-2026-4526: Silabs emberznet out-of-bounds read vulnerability

SSilabs · Emberznet

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

7.1 CVSS 4.0 High EPSS 0.44% · top 64.6% CWE-125 · Out-of-bounds read
7.1CVSS 4.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
25 Jun 2026Last modified by NVD

Description

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-4526 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51392Silabs emberznet broken cryptographic algorithm vulnerabilityEmber ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of …EPSS 0.24%9.8CVE-2023-41094Silabs emberznet vulnerabilityTouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effec…EPSS 0.58%9.8CVE-2022-24937Silabs emberznet memory buffer overflow vulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.EPSS 0.69%7.5CVE-2023-51393Silabs emberznet allocation without limits vulnerabilityDue to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v…EPSS 0.52%7.5CVE-2023-51394Silabs emberznet null pointer dereference vulnerabilityHigh traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.EPSS 0.52%7.5CVE-2022-24938Silabs emberznet memory buffer overflow vulnerabilityA malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.EPSS 0.75%7.1CVE-2026-47149Silabs emberznet out-of-bounds read vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process…EPSS 0.44%7.1CVE-2026-47150Silabs emberznet out-of-bounds write vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2026-4526), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.