Description
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
Problem types
Product status
Any version
4.60.023
Credits
Amir Zaltzman of Claroty Team82 reported these vulnerabilities to CISA.
References
enoceanwiki.atlassian.net/...0/SmartServer+IoT+Release+Notes
enoceanwiki.atlassian.net/...es/288063529/Enhancing+Security
www.cisa.gov/news-events/ics-advisories/icsa-26-050-01
github.com/...p/csaf_files/OT/white/2026/icsa-26-050-01.json