CVE-2026-47149
Door Lock GetUserType invalid table index in EmberZNet v9.0.2
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.
| CWE | CWE-125 |
| Vendor | silicon labs |
| Product | emberznet |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for silicon labs emberznet
Be the first to know when new unknown vulnerabilities affecting silicon labs emberznet are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Silicon Labs / EmberZNet
0 โค 9.0.2
References
Credits
Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University