CVE-2025-1394: Denial of Service (DoS) vulnerabilitiey in Zigbee library
Published Jul 30, 2025
·Updated
The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).
Affected Software
1 affected component
Silabs Emberznet
Event History
Jul 30, 2025
CVE Published
via MITRE·08:11 AM
Data Sourced
via MITRE·08:11 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1394?
CVE-2025-1394 is considered a medium severity vulnerability due to its potential for data leaks and Denial of Service (DoS).
2
How do I fix CVE-2025-1394?
Fixing CVE-2025-1394 involves upgrading to the latest version of the SiLabs EmberZNet Zigbee stack that addresses the buffer management API error handling issues.
3
What are the potential impacts of CVE-2025-1394?
The potential impacts of CVE-2025-1394 include data leaks and the possibility of a Denial of Service (DoS), which may disrupt service functionality.
4
Which software is affected by CVE-2025-1394?
CVE-2025-1394 specifically affects the SiLabs EmberZNet Zigbee stack.
5
Is there a workaround for CVE-2025-1394?
No official workaround is provided for CVE-2025-1394; updating to the patched version is recommended.