PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17610 Silicon Labs CVE debrief

A denial of service vulnerability exists in SiSDK v2026.6.0 and earlier, specifically for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread under high network traffic loads. This issue may cause a dropped ACK. Defenders should verify affected versions, assess exposure, and monitor for potential denial of service. Verification of affected SiSDK versions and device configurations is required to assess potential operational impacts, including denial of service under high network traffic loads.

Vendor
Silicon Labs
Product
SiSDK
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-09-08
Advisory published
2026-08-28
Advisory updated
2026-09-08

Who should care

Defenders responsible for EFR32MG24 and EFR32MG26 devices, particularly those using SiSDK v2026.6.0 and earlier, should assess exposure and verify affected versions.

Why it matters

CVE-2026-17610 is a denial of service vulnerability in SiSDK v2026.6.0 and earlier for EFR32MG24 and EFR32MG26 devices. Defenders should verify affected versions, assess exposure, and monitor for potential denial of service under high network traffic loads.

  • Verification of affected SiSDK versions and device configurations is required
  • Potential denial of service under high network traffic loads
  • Assessment of exposure for EFR32MG24 and EFR32MG26 devices

Technical summary

The vulnerability exists in SiSDK v2026.6.0 and earlier, specifically affecting EFR32MG24 and EFR32MG26 devices that are running concurrent multiprotocol Zigbee and Thread. High network traffic loads can cause a dropped ACK, leading to a denial of service.

Defensive priority

Defenders should prioritize verifying affected versions and assessing exposure for EFR32MG24 and EFR32MG26 devices.

Recommended defensive actions

  • Verify affected versions of SiSDK and assess exposure for EFR32MG24 and EFR32MG26 devices
  • Monitor network traffic loads and ACK responses for potential denial of service
  • Review device configurations for concurrent multiprotocol Zigbee and Thread usage

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, specific remediation steps or affected versions require verification from official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.