PT-2026-52401 · Unknown · Ember Znet

CVE-2026-47148

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions EmberZNet versions prior to 9.0.3
Description Malformed GetGroupMembership commands can cause repeated reads beyond the end of the message payload, leading to process termination. This issue affects only devices that support the Groups cluster and requires the messages to originate from a device that has already joined the network. No information leakage to the sender was observed.
Recommendations Update EmberZNet to a version newer than 9.0.2.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47148

Affected Products

Ember Znet