Home

Description

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

PUBLISHED Reserved 2026-02-12 | Published 2026-02-20 | Updated 2026-02-20 | Assigner icscert




HIGH: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-77

Product status

Default status
unaffected

Any version
affected

4.60.023
unaffected

Credits

Amir Zaltzman of Claroty Team82 reported these vulnerabilities to CISA. finder

References

enoceanwiki.atlassian.net/...0/SmartServer+IoT+Release+Notes

enoceanwiki.atlassian.net/...es/288063529/Enhancing+Security

www.cisa.gov/news-events/ics-advisories/icsa-26-050-01

github.com/...p/csaf_files/OT/white/2026/icsa-26-050-01.json

cve.org (CVE-2026-20761)

nvd.nist.gov (CVE-2026-20761)

Download JSON