CVE-2025-7964
After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommissioning is required to recover the Zigbee Router.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.26%
- CWE
- CWE-229
- Published
- 2026-01-30
- Last modified
- 2026-03-12
Affected products
- silabs.com Silicon Labs Zigbee Stack
Weakness type
Related vulnerabilities
- CVE-2026-59566 — Local denial-of-service
- CVE-2026-59565 — Local and kernel denial-of-service
- CVE-2025-35973 — Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare...
- CVE-2026-4736 — Math Issue in No-Chicken/Echo-Mate
- CVE-2025-31648 — Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an...
- CVE-2025-20268 — Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability
- CVE-2024-20431 — A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD)...
- CVE-2024-39531 — Junos OS Evolved: ACX 7000 Series: Protocol specific DDoS configuration affects other protocols