Description
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.
Published: 2026-06-25
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when EmberZNet v9.0.2 and earlier process malformed ClearWeekdaySchedule messages. The malformed packet triggers an out-of-bounds write into the Door Lock schedule state, a classic buffer over-read/writer issue identified as CWE-787. Because the overwrite targets internal scheduling data, an attacker can corrupt lock state or cause a denial of service by permanently altering or destabilizing the lock’s schedule. The damage is limited to the integrity of the schedule data rather than arbitrary code execution, but the resulting malfunction could lead to lock failure or unauthorized behaviour.

Affected Systems

Devices running Silicon Labs EmberZNet firmware v9.0.2 or earlier that implement the Door Lock cluster are affected. The vulnerability is exploited only by messages originating from a device that has already joined the network and that supports the Door Lock cluster; devices lacking that cluster are not impacted.

Risk and Exploitability

The static severity is moderate‑high with a CVSS score of 7.1. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a device with network access that can send the specific malformed ClearWeekdaySchedule command. Therefore the attack vector is most likely local, stemming from a compromised or malicious networked device. Given the lack of a public exploit and the limited payload of the out-of-bounds write, the likelihood of widespread exploitation is low, but the potential impact on lock reliability remains significant.

Generated by OpenCVE AI on June 25, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the EmberZNet firmware to the latest vendor‑supplied version that contains the fix for malformed ClearWeekdaySchedule handling.
  • Apply network segmentation or firewall rules to limit which devices can communicate with the Door Lock cluster, reducing the attack surface for malicious messages.
  • Configure network or device monitoring to detect unusual ClearWeekdaySchedule traffic and alert administrators when malformed packets are observed.
  • If the Door Lock functionality is not essential, disable the Door Lock cluster or the ClearWeekdaySchedule command on affected devices as a temporary control.

Generated by OpenCVE AI on June 25, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.
Title Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-06-25T14:17:02.671Z

Reserved: 2026-05-18T20:02:03.669Z

Link: CVE-2026-47151

cve-icon Vulnrichment

Updated: 2026-06-25T14:16:57.481Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T15:30:16Z

Weaknesses