CVE-2026-47145: Color Control hue/saturation assertion abort in EmberZNet v9.0.2
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47145?
CVE-2026-47145 has a severity rating of high, with a CVSS score of 7.1.
What are the potential impacts of CVE-2026-47145?
CVE-2026-47145 may cause the process to terminate when malformed Color Control messages are received.
How do I fix CVE-2026-47145?
To address CVE-2026-47145, update to EmberZNet version 9.0.3 or later, which resolves this vulnerability.
Who is affected by CVE-2026-47145?
Devices that support the Color Control cluster and are running EmberZNet v9.0.2 or earlier are affected by CVE-2026-47145.
What types of devices can trigger the CVE-2026-47145 vulnerability?
Only devices that have already joined the network and support the Color Control cluster can trigger the CVE-2026-47145 vulnerability.