Impact
The vulnerability is a missing acknowledgment within the RAIL 802.15.4 multiplexer in SiSDK versions 2026.6.0 and earlier, which can cause an ACK drop when the network experiences high traffic loads, resulting in a denial of service. The flaw is limited to devices EFR32MG24 and EFR32MG26 that run concurrent Zigbee and Thread protocols, and it can interrupt normal operation by halting communication or causing device resets.
Affected Systems
Silicon Labs SiSDK up to version 2026.6.0, running on EFR32MG24 and EFR32MG26 microcontrollers when both Zigbee and Thread are enabled concurrently.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, while an EPSS score was not available, suggesting low or unknown exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker or a side‑channel to generate or sustain high traffic on the target device, likely from within the local network, to trigger the ACK drop and induce the denial of service.
OpenCVE Enrichment