CVE-2026-47147
OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.
| CWE | CWE-125 |
| Vendor | silicon labs |
| Product | emberznet |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for silicon labs emberznet
Be the first to know when new unknown vulnerabilities affecting silicon labs emberznet are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Silicon Labs / EmberZNet
0 โค 9.0.2
References
Credits
Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University