community.silabs.comVendor advisorypermissions required
https://community.silabs.com/068Vm00000dspiL CVE-2025-7964
CRITICAL
Zigbee Router Denial of Service
Record summary
CVE-2025-7964 has a selected CVSS score of 9.2 (critical).
Description
After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommissioning is required to recover the Zigbee Router.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 4.4.6 | affected |
Default status: unaffected | CVE List | Through 2025.6.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-7964