Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Silicon Labs — Vulnerabilities & Security Advisories 45

Browse all 45 CVE security advisories affecting Silicon Labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Silicon Labs designs microcontrollers, wireless connectivity solutions, and analog integrated circuits primarily for industrial, automotive, and consumer IoT applications. With thirty-one recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has frequently involved remote code execution and buffer overflow flaws within its wireless stack and development tools. These vulnerabilities often stem from insufficient input validation in embedded firmware or misconfigured default credentials in debugging interfaces. While no catastrophic, widespread data breaches have been publicly attributed to the vendor, the nature of its hardware-centric products means that exploited flaws can potentially compromise physical device integrity or enable unauthorized network access. Security updates are typically distributed via firmware patches, requiring careful integration by downstream manufacturers to mitigate risks associated with legacy components and unpatched wireless protocols.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6432 Improper bounds validation in EmberZNet SDK — SiSDKCWE-130--2026-06-25
CVE-2026-47154 Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 — EmberZNetCWE-125--2026-06-25
CVE-2026-47153 Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 — EmberZNetCWE-369--2026-06-25
CVE-2026-47152 Level Control Move divide-by-zero in EmberZNet v9.0.2 — EmberZNetCWE-369--2026-06-25
CVE-2026-47151 Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 — EmberZNetCWE-787--2026-06-25
CVE-2026-47150 IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 — EmberZNetCWE-787--2026-06-25
CVE-2026-47149 Door Lock GetUserType invalid table index in EmberZNet v9.0.2 — EmberZNetCWE-125--2026-06-25
CVE-2026-47148 Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 — EmberZNetCWE-125--2026-06-25
CVE-2026-47147 OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2 — EmberZNetCWE-125--2026-06-25
CVE-2026-47146 Color Control color-temperature assertion abort in EmberZNet v9.0.2 — EmberZNetCWE-617--2026-06-25
CVE-2026-47145 Color Control hue/saturation assertion abort in EmberZNet v9.0.2 — EmberZNetCWE-617--2026-06-25
CVE-2026-4526 Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 — EmberZNetCWE-125--2026-06-25
CVE-2026-2815 Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys — SiSDKCWE-339--2026-06-25
CVE-2026-3290 Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values — RS9116 SDKCWE-332--2026-05-14
CVE-2025-2838 Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability — Gecko OSCWE-835 6.5AIMediumAI2025-03-26
CVE-2025-2837 Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability — Gecko OSCWE-121 8.8AIHighAI2025-03-26
CVE-2024-9055 DPA Countermeasures need reseeding — Simplicity SDKCWE-331 4.2 Medium2025-03-17
CVE-2024-12975 Silicon Labs CPC can leak information in full duplex SPI — Simplicity SDKCWE-126 6.5 -2025-03-07
CVE-2024-23937 Silicon Labs Gecko OS Debug Interface Format String — Gecko OSCWE-200 4.3 Medium2025-01-31
CVE-2024-23973 Silicon Labs Gecko OS HTTP GET Request Handling Stack-based Buffer Overflow — Gecko OSCWE-120 8.8 High2025-01-30
CVE-2024-24731 Silicon Labs Gecko OS http_download Stack-based Buffer Overflow — Gecko OSCWE-120 7.5 High2025-01-30
CVE-2024-23938 Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability — Gecko OSCWE-121 8.8 High2024-09-28
CVE-2023-41093 Loss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuse — Simplicity SDKCWE-416 3.1 Low2024-07-12
CVE-2024-22472 Long S0 frames received by 500 series Z-Wave devices may cause buffer overflow — Z-Wave SDKCWE-120 8.1 High2024-05-07
CVE-2023-51395 Z-Wave S0 Decryption Vulnerability in End Devices — Z-Wave SDKCWE-787 8.8 High2024-03-07
CVE-2023-39541 Weston Embedded uC-TCP-IP 安全漏洞 — Gecko PlatformCWE-126 5.9 Medium2024-02-20
CVE-2023-39540 Weston Embedded uC-TCP-IP 安全漏洞 — Gecko PlatformCWE-126 5.9 Medium2024-02-20
CVE-2023-45318 Weston Embedded uC-HTTP 安全漏洞 — Gecko PlatformCWE-122 10.0 Critical2024-02-20
CVE-2023-24585 Micrium uC-HTTP 缓冲区错误漏洞 — Gecko PlatformCWE-119 7.7 High2023-11-14
CVE-2023-28391 Weston Embedded uC-HTTP 缓冲区错误漏洞 — Gecko PlatformCWE-119 9.0 Critical2023-11-14

This page lists every published CVE security advisory associated with Silicon Labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.