EmberznetApplication · Silabs

CVE-2026-4526

MEDIUM · 6.5 CVSS v3.1 Published 2026-06-25
Fix available
A fix is available. Upgrade to after 9.0.2 or later.
See remediation →
71/100
Remediation priority · Elevated
Remotely reachable Zero-click 8 weeks old

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · moderate confidence

In EmberZNet v9.0.2 and earlier, malformed global ZCL (Zigbee Cluster Library) messages from an authenticated device (one already joined the network) trigger out-of-bounds reads in the framework's ZCL parsing logic, causing the process to terminate.

MitigationUpdate to EmberZNet v9.0.3 or later once available; restrict network join permissions and monitor for anomalous ZCL message patterns from joined devices.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
EmberznetApplication
Affected:<= 9.0.2

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify EmberZNet version
    Locate the EmberZNet SDK or firmware version in your build artifacts, device firmware metadata, or release documentation. This is typically found in the firmware build files, release notes, or the EmberZNet SDK installation directory.
    Affected if The installed version is 9.0.2 or earlier.
  2. Verify Zigbee network role
    Determine if the device is configured as a coordinator, router, or end device that allows other devices to join and communicate. Check the network configuration settings or NCP (Network Co-Processor) firmware settings.
    Affected if The device participates as a coordinator or router that accepts authenticated (joined) devices and processes their ZCL messages.
  3. Confirm ZCL global message processing is active
    Review the application configuration to confirm that global ZCL command handling (such as read attributes, write attributes, or configure reporting commands) is enabled in the ZCL implementation.
    Affected if Global ZCL command parsing is enabled in the ZCL framework.
  4. Check for authenticated device acceptance
    Examine the network join permissions or trust center settings to determine whether the device allows other devices to join as authenticated network members.
    Affected if The device permits other devices to join and become authenticated network members that can send ZCL messages.

You are affected if your EmberZNet version is 9.0.2 or earlier and your device accepts authenticated Zigbee devices that can send global ZCL messages to trigger the out-of-bounds read vulnerability.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to a release after 9.0.2
Interim mitigation

Update to EmberZNet v9.0.3 or later once available; restrict network join permissions and monitor for anomalous ZCL message patterns from joined devices.

Recommended fix Moderate confidence

Latest EmberZNet release (version > 9.0.2, check Silicon Labs for current GA release)

  1. 1. Identify the current EmberZNet version in your deployment by checking the stack version in your EmberZNet-based gateway or hub firmware.
  2. 2. Download the latest EmberZNet stack release from Silicon Labs (available via their website or GitHub repositories under SiliconLabs)
  3. 3. Review the release notes for the latest version to confirm the out-of-bounds read vulnerability (CVE-2026-4526) is addressed.
  4. 4. Before deploying, validate the new firmware version in a test environment to ensure compatibility with your Zigbee devices and network configuration.
  5. 5. Plan a maintenance window as the firmware update may require rejoin of Zigbee devices.
  6. 6. Apply the firmware update to all affected EmberZNet-based devices in your network.
  7. 7. After update, verify that Zigbee network operations are functioning normally and no devices are experiencing issues.
Caveat Review release notes for any stack behavior changes that may affect existing device compatibility or custom ZCL implementations; some device rejoin may be required

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Emberznet Scoped from the published advisory
  • Consultation4.0 h
  • Implementation8.0 h
  • Testing6.0 h
  • Review / QA4.0 h
22.0 hours of engineering $3,860
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $6,176.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-4526 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-4526 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data