CVE-2026-20761

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-20 16:22

Updated : 2026-02-20 16:55


NVD link : CVE-2026-20761

Mitre link : CVE-2026-20761

CVE.ORG link : CVE-2026-20761


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')