CVE-2025-8414: Silabs.com Gecko SDK

Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability.

Affected products

  • Silabs.com Gecko SDK: up to and including 4.4.6
  • Silabs.com Simplicity SDK: up to and including 2025.6.0; up to and including 2024.12.2

Published 2025-10-17. Last modified 2026-06-17.