CVE-2026-47147: OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47147?
CVE-2026-47147 has a high severity rating of 7.1 according to the CVSS.
How do I fix CVE-2026-47147?
To fix CVE-2026-47147, update EmberZNet to version 9.0.3 or later, which includes the necessary patches.
What type of vulnerability is CVE-2026-47147?
CVE-2026-47147 is classified as a missing per-field bounds validation vulnerability in the OTA server raw parser.
What are the potential consequences of CVE-2026-47147?
Exploitation of CVE-2026-47147 may allow an attacker to read limited sensitive data from RAM through malformed OTA requests.
Who is affected by CVE-2026-47147?
CVE-2026-47147 affects users of EmberZNet version 9.0.2 and earlier, particularly with OTA server functionalities.