Vulnerability Description
After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommissioning is required to recover the Zigbee Router.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-7964?
CVE-2025-7964 is a documented vulnerability. After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state...
How severe is CVE-2025-7964?
CVSS scoring is not yet available for CVE-2025-7964. Check NVD for updates.
Is there a patch for CVE-2025-7964?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.