CVE-2025-14547: Silabs.com Gecko SDK

Low severity, CVSS 2.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.

Affected products

  • Silabs.com Gecko SDK: before 2.6 (fixed in 2.6)
  • Silabs.com Simplicity SDK: up to and including 2025.6.2

Published 2026-02-20. Last modified 2026-06-17.