CVE-2026-47151: Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47151?
CVE-2026-47151 has a risk score of 34, indicating a moderate severity level.
How do I fix CVE-2026-47151?
To mitigate CVE-2026-47151, upgrade to the latest version of EmberZNet that addresses the vulnerability.
What is CVE-2026-47151 about?
CVE-2026-47151 involves out-of-bounds write vulnerabilities in the Door Lock schedule state due to malformed ClearWeekdaySchedule messages.
Which devices are affected by CVE-2026-47151?
CVE-2026-47151 affects devices that utilize the EmberZNet v9.0.2 or earlier versions with Door Lock capabilities.
When was CVE-2026-47151 published?
CVE-2026-47151 was published on June 25, 2026.