prior, which would allow remote attackers, in the LON IP-852 management
messages, to send specially crafted IP-852 messages resulting in
arbitrary OS command execution on the device.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
EnOcean recommends users update the SmartServer platform software to SmartServer 4.6 Update 2 (v4.60.023) or a later release at https://enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notes#... https://enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notes#Current-Stable-Release .
Vendor Workaround
For additional mitigations and workarounds, refer to EnOcean's hardening guide at https://enoceanwiki.atlassian.net/wiki/spaces/IEC/pages/288063529/Enhancing+Security .
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enocean Edge
Enocean Edge smartserver Iot |
|
| Vendors & Products |
Enocean Edge
Enocean Edge smartserver Iot |
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device. | |
| Title | EnOcean SmartServer IoT Command Injection | |
| Weaknesses | CWE-77 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-02-20T20:09:15.218Z
Reserved: 2026-02-12T00:19:51.025Z
Link: CVE-2026-20761
Updated: 2026-02-20T20:08:48.192Z
Status : Deferred
Published: 2026-02-20T16:22:32.243
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-20761
No data.
OpenCVE Enrichment
Updated: 2026-04-17T17:30:23Z