A
vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
References
Configurations
No configuration.
History
20 Feb 2026, 16:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 16:22
Updated : 2026-02-20 16:55
NVD link : CVE-2026-20761
Mitre link : CVE-2026-20761
CVE.ORG link : CVE-2026-20761
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')