PT-2026-52401 · Unknown · Ember Znet
CVE-2026-47148
·
Published
2026-06-25
·
Updated
2026-06-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
EmberZNet versions prior to 9.0.3
Description
Malformed GetGroupMembership commands can cause repeated reads beyond the end of the message payload, leading to process termination. This issue affects only devices that support the Groups cluster and requires the messages to originate from a device that has already joined the network. No information leakage to the sender was observed.
Recommendations
Update EmberZNet to a version newer than 9.0.2.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ember Znet