PT-2026-58846 · Unknown · Matter Sdk
CVE-2025-56362
·
Published
2026-07-14
·
Updated
2026-07-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Matter SDK (connectedhomeip) versions prior to 1.4.2
Description
A reachable assertion issue exists within the Level Control cluster's periodic server tick logic. A remote, unauthenticated attacker can cause a denial of service by sending a MoveToLevel command followed immediately by a write of
OperationMode=2 in the Pump Configuration and Control cluster. This sequence causes the server tick function to violate the assertion currentLevel < maxLevel, leading to a system crash.Recommendations
Update Matter SDK (connectedhomeip) to version 1.4.2 or later.
Exploit
Fix
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matter Sdk