High traffic causes corrupt SPI packets in OpenThread leading to denial of service

CVE Details

Basic Information

Title High traffic causes corrupt SPI packets in OpenThread leading to denial of service
Type cve
Published 2025-07-25T15:49:40.236Z
Modified 2025-07-25T15:49:40.236Z

Product Information

Vendor silabs.com
Product OpenThread
Version 2.5.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products

  • silabs.com OpenThread 2.5.0
  • silabs.com OpenThread 2.6.0
  • silabs.com OpenThread 0

Additional Information

CWE List CWE-908
Source Silabs

Description

In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and may send a corrupt packet over SPI to its host,  causing the host to reset the RCP which results in a denial of service.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.