CVE-2026-47150: IAS Zone enroll invalid table index and write in EmberZNet 9.0.2
Published Jun 25, 2026
·Updated
In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.
Affected Software
2 affected components
EmberZNet<=9.0.2
Silabs Emberznet<=9.0.2
Event History
Jun 25, 2026
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-47150?
CVE-2026-47150 has a risk rating of 31.
2
How do I fix CVE-2026-47150?
To fix CVE-2026-47150, update to the latest version of EmberZNet that addresses the vulnerability.
3
What causes the CVE-2026-47150 vulnerability?
CVE-2026-47150 is caused by malformed IAS Zone enrollment messages that trigger out-of-bounds writes.
4
Which software is affected by CVE-2026-47150?
CVE-2026-47150 affects EmberZNet versions 9.0.2 and earlier.
5
Can CVE-2026-47150 be exploited remotely?
Yes, CVE-2026-47150 can be exploited by devices that have already joined the network.