Description
In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread.
Published: 2026-08-27
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing acknowledgment within the RAIL 802.15.4 multiplexer in SiSDK versions 2026.6.0 and earlier, which can cause an ACK drop when the network experiences high traffic loads, resulting in a denial of service. The flaw is limited to devices EFR32MG24 and EFR32MG26 that run concurrent Zigbee and Thread protocols, and it can interrupt normal operation by halting communication or causing device resets.

Affected Systems

Silicon Labs SiSDK up to version 2026.6.0, running on EFR32MG24 and EFR32MG26 microcontrollers when both Zigbee and Thread are enabled concurrently.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, while an EPSS score was not available, suggesting low or unknown exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker or a side‑channel to generate or sustain high traffic on the target device, likely from within the local network, to trigger the ACK drop and induce the denial of service.

Generated by OpenCVE AI on August 28, 2026 at 06:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiSDK to a version newer than 2026.6.0.
  • If the upgrade is not feasible, disable concurrent Zigbee and Thread protocols to prevent high traffic that can cause ACK drops.
  • Monitor network traffic for spikes and consider rate‑limiting or traffic shaping to reduce the likelihood of ACK loss.

Generated by OpenCVE AI on August 28, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Silicon Labs
Silicon Labs sisdk
Vendors & Products Silicon Labs
Silicon Labs sisdk

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread.
Title RAIL 802.15.4 Mux missing ACK can lead to DoS
Weaknesses CWE-404
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Silicon Labs Sisdk
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-28T15:29:13.052Z

Reserved: 2026-07-27T17:25:40.218Z

Link: CVE-2026-17610

cve-icon Vulnrichment

Updated: 2026-08-28T15:29:09.595Z

cve-icon NVD

Status : Received

Published: 2026-08-28T00:16:48.470

Modified: 2026-08-28T20:17:22.733

Link: CVE-2026-17610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:30:18Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release